Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
Cantina
CodeHawks
Jan '25
high
high
medium
high
Dec '24
high
Nov '24
medium
Oct '24
Jul '24
medium
Discrepency b/w the `lastRewadTime` and the `lastAllPoolUpdate` can allow for incorrect reward distribution to pools if `registerRewardDeposit` deposits less assets
medium
Usage of `lastEligibleStatus` can cause user to miss out on rewards on `manualStopEmissionsFor` invocation
medium
In CDPVault::liquidatePositionBadDebt(), the calculation of `loss` is incorrect.
medium
PositionAction.decreaseLever() fails to consider the loan fee in Flashlender when calculating loanAmount, as a result, the functionanlity will not work when protocolFee != 0.
Jun '24
May '24
Apr '24
Mar '24
medium
Asymmetric calculation of price difference
medium
dailyDebtIncreaseLimitLeft is not updated in liquidate().
medium
Repayments and liquidations can be forced to revert by an attacker that repays miniscule amount of shares
medium
Due to interest rates update method, Interest-Free Loans are possible and the Cost of DoS are reduced
medium
An attacker can easily bypass the collateral value limit factor checks
Feb '24
medium
high
Since you can reroll with a different fighterType than the NFT you own, you can reroll bypassing maxRerollsAllowed and reroll attributes based on a different fighterType
medium
NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)
medium
Constraints of dailyAllowanceReplenishTime and allowanceRemaining during mint() can be bypassed by using alias accounts & safeTransferFrom()
Jan '24
high
When borrowers repay USDS, it is sent to the wrong address, allowing anyone to burn Protocol Owned Liquidity and build bad debt for USDS
high
User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated
medium
DOS of proposals by abusing ballot names without important parameters
Nov '23
207.11 USDC • 1 total finding • Code4rena • lanrebayode77
#17
Oct '23
Sep '23
Aug '23
Jul '23
Jun '23
May '23