High
Solo
Total
Medium
Solo
Total
Total Earnings
#102 All Time
Payouts
1st Places
2nd Places
Top 10
All
Sherlock
Code4rena
CodeHawks
Aug '25
Collaborative Audit • Sherlock • jokr
Jul '25
Collaborative Audit • Sherlock • jokr
Jun '25
Collaborative Audit • Sherlock • jokr
May '25
high
The `userBorrowedAssets` array is incorrectly updated during borrow repayments.
high
`seizeTokens` are calculated with incorrect exchange rate during cross-chain liquidations.
high
Accrued rewards not reset to zero after claim
high
supply and redeem functions are using outdated exchangeRate.
high
Wrong amount of borrow will be repaid by liquidator during cross-chain liquidation
high
Incorrect ltoken address used in cross-chain liquidation success message causes liquidation failure
high
During cross-chain borrow repayments/liqudations same-chain borrows are accidentally being cleared
high
cross-chain borrows are stored with reversed srcEid and destEid, causing them to be ignored in debt calculations
high
A malicious user can withdraw his collateral in between a cross-chain borrow.
high
cross-chain liquidators can steal funds without actually repaying debt
high
No way to withdraw protocol rewards for the admin
high
Incorrect LEND reward accounting.
high
Incorrect borrow accounting due to missing interest accrual on cross-chain borrows
high
Incorrect cross-chain collateral lookup in liquidation success handler causes revert
high
Healthy positions will be liquidated due to wrong liquidation check
high
Cross-chain liquidations will be blocked due to incorrect maxLiquidatable amount calculation.
high
Invariant in borrowWithInterest can be violated causing DoS
high
Interest for cross-chain borrow is calculated with wrong index.
high
Incorrect LEND reward distribution for cross-chain borrows
high
Incorrect liquidity check during cross-chain borrows leads to bad debt
high
CoreRouter must use a lower LTV than Compound to prevent liquidations and accounting failure
medium
Borrower will loose funds if their repay transaction executes after cross-chain liquidation call
medium
Incorrect borrow amount calculation leads false liquidations.
medium
Incorrect calculations of allowed liquidatable amount
medium
Incorrect liquidity check on destination chain.
Collaborative Audit • Sherlock • jokr
Collaborative Audit • Sherlock • jokr
Feb '25
Collaborative Audit • Sherlock • jokr
Dec '24
high
An attacker can drain NumaVault right after deployment
high
cLST market can be drained using a fake collateral token address in leverageStrategy function
medium
leverageStrategy will revert due users interest rate accrual
medium
Precision loss in setMaxSpotOffsetBps function leads to Incorrect Numa Prices
medium
No slippage check for leverageStrategy function
medium
Numa tokens fee on transfer can be bypassed
Oct '24
Findings not publicly available for private contests.
Jul '24
high
`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`
high
The Bridging Process will revert if the Collection is matched on the destination chain and not matched on the source chain
high
Infinite loop breaks whitelist removal funtionality on L2
high
`Bridge` is unable to transfer ownership and upgrade on `ERC721Bridgeable`
medium
Starknet tokens deposited with use_withdraw_auto can never be withdrawn
medium
Tokens irrecoverable by owner on L1 if not an `ERC721` receiver
low
Upon the transfer of an escrowed NFT from the bridge to the user on StarkNet, the escrow status remains unaltered, failing to be reset
Findings not publicly available for private contests.
Apr '24
high
The amount of `xezETH` in circulation will not represent the amount of `ezETH` tokens 1:1
high
Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps
high
Incorrect calculation of queued withdrawals can deflate TVL and increase ezETH mint rate
medium
stETH/ETH Feed being used opens up to 2 way deposit<->withdrawal arbitrage
medium
Deposits will always revert if the amount being deposited is less than the bufferToFill value
medium
Lack of slippage and deadline during withdraw and deposit
Feb '24
Dec '23
Collaborative Audit • Sherlock • jokr