Payouts
Top 25
Top 50
All
Sherlock
Code4rena
CodeHawks
Aug '24
high
TokenManager - Unlimited withdraw
high
Taker of bid offer will loss assets without any benefit if he calls the DeliveryPlace::settleAskMaker() for partial settlement.
high
Formulaic Error Rounds Down Causing Total Loss Of Funds For Bid Takers During Abort
high
Missing abort status check allows bid taker to steal users funds
low
`listOffer` Unsafely References Fungible Identifiers
Jul '24
high
`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`
high
The maximum number of generations is infinite
high
Number of entities in generation can surpass the 10k number
high
Griefing attack on seller's airdrop benefits
high
Wrong minting logic based on total token count across generations
medium
Forger Entities can forge more times than intended
medium
Imprecise token age calculation results in an incorrect nuke factor, causing users to claim the wrong amount
medium
Discrepancy between nfts minted, price of nft when a generation changes & position of `_incrementGeneration()` inside `_mintInternal()` & `_mintNewEntity()`
Jun '24
high
Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect
medium
`executeBuyCreditMarket` returns the wrong amount of cash and overestimates the amount that needs to be checked in the variable pool
medium
Users can not to buy/sell minimum credit allowed due to exactAmountIn condition
medium
Multicall does not work as intended
medium
withdraw() users may can't withdraw underlyingBorrowToken properly
Apr '24
Feb '24
Jan '24
Dec '23
medium
Fees are hardcoded to 3000 in ExactInputSingleParams
medium
Wrong Implementation of `LiquidationPool::empty` excludes holder with pending stakes when decreasing a position, resulting in exclusion from asset distribution
low
Removal of approved token from token manager can lead to unintended liquidation of vaults
Nov '23
1.37 USDC • 1 total finding • Code4rena • inzinko
#31
Oct '23
Sep '23