Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
Cantina
Nov '24
Findings not publicly available for private contests.
Oct '24
Findings not publicly available for private contests.
Sep '24
Jul '24
May '24
high
DOS in the claimWithdraw function due to an incorrect check of the lastFinalizedRequestId in the EEtherAdapter.sol
medium
The _stake function in the PufETHAdapter will always fail
medium
PufETHAdapter does not handle the case when the stakeLimit of stETH is zero correctly
medium
DOS vulnerability in the _stake function in RsETHAdapter.sol
medium
UniETHAdapter and RsETHAdapter do not have slippage protection
Apr '24
high
The LenderCommitmentGroup_Smart smart contract may lose principal tokens in EscrowVault.sol
high
Liquidators utilizing the liquidateDefaultedLoanWithIncentive function do not receive the collateral tokens
high
Lenders have the ability to manipulate any LenderCommitmentGroup_Smart contract using the repayLoanCallback()
high
Frontrun the repayment or liquidation functions to withdraw a portion of the interest in a single block
medium
The FlashRolloverLoan_G5 smart contract invokes a function that has not been implemented
medium
The SmartCommitmentForwarder smart contract isn't compatible with FlashRolloverLoan_G5.sol
medium
Fee on transfer tokens isn't compatible with LenderCommitmentGroup_Smart.sol
medium
DOS vulnerability in the rolloverLoanWithFlash function in FlashRolloverLoan_G5.sol
Mar '24
high
high
high
high
medium
medium
medium
high
lotRouting will be always with lotId = 0 in Auctioneer smart contract
high
The protocol is losing all the gas fees from all modules and derivatives on the Blast chain
high
routing.funding overflow after AuctionHouse.curate function
medium
All base and quote tokens are stuck due to a blacklisted pfBidder in the EMPAM
medium
Malicious seller can freeze quote tokens in EMPAM
Feb '24
Oct '23
high
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
medium
On a Linear or Exponential Descending Sale Model, a user that mint on the last `block.timestamp` mint at an unexpected price.
medium
Bidder Funds Can Become Unrecoverable Due to 1 second Overlap in `participateToAuction()` and `claimAuction()`
Sep '23
Aug '23
Jan '23
Nov '22