Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Sep '23
Aug '23
Jul '23
Jun '23
May '23
Apr '23
Mar '23
high
A temporary issue shows in the staking functionality which leads to the users receiving less minted tokens.
high
Staking, unstaking and rebalanceToWeight can be sandwiched (Mainly rETH deposit )
high
`WstEth` derivative assumes a ~1=1 peg of stETH to ETH
high
Price of sfrxEth derivative is calculated incorrectly
high
Users can fail to unstake and lose their deserved ETH because malfunctioning or untrusted derivative cannot be removed
medium
Division before multiplication truncate minOut and incurs heavy precision loss and result in insufficient slippage protection
medium
Residual ETH unreachable and unuitilized in SafEth.sol
Feb '23
medium
DOS to executeDeposit if diff is more than longTokenAmount
medium
getAdjustedLongAndShortTokenAmounts will always revert
medium
loss of funds to user when depositing in a market that uses the same long token and short token
medium
when execute deposit fails, cancel deposit will be called which means that execution fee for keeper will be little for executing the cancellation depending on where the executeDeposit fails
high
stuck underlying tokens in BlueBerryBank when withdrawLend is called
high
incorrect logic in withdrawInternal can cause wrong amount lp to be withdrawn from IchiVault for swap
medium
lack of slippage control can cause uniswap swap to be susceptible to sandwich attacks
medium
onlyEOAEx modifier that ensures call is from EOA might not hold true in the future
medium
missing implementation in HardVault causes it to serve no purpose
medium
max position size of strategy can be bypassed if oracle returns 0
medium
chainlink oracle does not check answer returned is not 0
Jan '23
Dec '22
high
Inflation of ggAVAX share price by first depositor
medium
wrong reward distribution between early and late depositors because of the late syncRewards() call in the cycle, syncReward() logic should be executed in each withdraw or deposits (without reverting)
medium
slashing fails when node operator doesn't have enough staked `GGP`
high
Reentrancy in buy function for ERC777 tokens allows buying funds with considerable discount
high
Liquidity providers may lose funds when adding liquidity
high
First depositor can break minting of shares
medium
Price will not always be 18 decimals, as expected and outlined in the comments
medium
Rounding error in buyQuote might result in free tokens
Nov '22
high
BringUnusedETHBackIntoGiantPool can cause stuck ether funds in Giant Pool
high
Incorrect accounting in SyndicateRewardsProcessor results in any LP token holder being able to steal other LP tokens holder's ETH from the fees and MEV vault.
medium
DAO or lsdn owner can steal funds from node runner
medium
Giant pools cannot receive ETH from vaults