Payouts
1st Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Dec '24
high
LamboFactory can be permanently DoS-ed due to createPair call reversal
high
Minting zero tokens when underlyingToken is not Ether in cashIn()
medium
Since the cost of launching a new pool is minimal, an attacker can maliciously consume VirtualTokens.
medium
Accumulated ETH in the LamboVEthRouter will be irretrievable
medium
Attacker can captures `VETH-WETH` depeg profits through a malicious pool, rendering rebalancer useless if VETH Price > WETH Price
Nov '24
Oct '24
high
Subtraction in `variance()` will revert due to underflow
high
Potential underflow vulnerability in score range calculation of `LLMOracleCoordinator::finalizeValidation`, leading to DoS.
medium
Request responses and validations can be mocked leading to extraction of fees and/or forcing other generators to lose their fees by making them outliers
medium
Unrestricted validation score range for validators in `LLMOracleCoordinator::validate`.
medium
Users can list assets with price < 1 ERC20 (ETH, WETH), leading to potential DoS vulnerability.
low
Inaccurate best response selection in `LLMOracleCoordinator::getBestResponse`.
low
Inconsistent Best Response Selection Due to Missing Tiebreak Mechanism
Aug '24
medium
medium
medium
Jul '24
high
`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`
high
The Bridging Process will revert if the Collection is matched on the destination chain and not matched on the source chain
medium
There is No `msg.value` check in `depositTokens`, causing potential token stuck
Jun '24
Oct '23