Payouts
2nd Places
3rd Places
Top 10
All
Sherlock
Code4rena
Cantina
CodeHawks
Immunefi
Mar '25
high
high
Feb '25
high
Jan '25
high
Findings not publicly available for private contests.
Findings not publicly available for private contests.
Dec '24
Findings not publicly available for private contests.
high
Replay attack vulnerability in `withdraw` function due to nonce mismanagement, in `CDS` contract
high
Arbitrary price manipulation in `redeemUSDT` function enables treasury drain
high
Missing access control in `updateDownsideProtected` allows arbitrary manipulation
high
Exploitable high `strikePrice` input allows borrowers to minimize withdrawals
medium
Incorrect borrower count and withdrawal issues due to improper flag handling in `treasury` contract
medium
Inconsistent `lastEthprice` updates impact omnichain data calculations
medium
`calculateCumulativeRate` always returns `lastCumulativeRate` due to incorrect `lastEventTime` update
medium
Excess ether not refunded to users in `depositTokens` function
Nov '24
high
Fee calculation vulnerability will overcharge users during vote purchases
high
Attacker can gain a advantage by manipulating the order in which votes are bought and sold.
medium
`slash` function lacks 24-hour lock mechanism for accused staking and withdrawals
medium
Multiple fee miscalculation leads to inaccurate implementation of the fee model
high
high
Missing NFT claim mechanism prevents buy order owners from accessing transferred NFTs
medium
Valid lenders and borrowers may not receive their incentives due to sequence of `lenders`
medium
Lack of handling for unclaimed incentives causes permanent lockup of funds
medium
Loan extension miscalculation will cause reversion of extendLoan
medium
Borrowers will face excessive principal loss due to incorrect fee calculation(`feeOfMaxDeadline`) in loan extension
medium
Inconsistent `isActive` state in `DLOImplementation` enables repeated exploitation of `changePerpetual` to clear factory lend orders
medium
Incorrect calculation of extended loan days leads to unfair borrower fees
medium
Incorrect interest handling after loan extension leads to lender losses
medium
Attacker manipulates precision loss to overcharge borrower on APR
Oct '24
high
Subtraction in `variance()` will revert due to underflow
high
Potential underflow vulnerability in score range calculation of `LLMOracleCoordinator::finalizeValidation`, leading to DoS.
medium
Platform fees withdrawal will sweep oracle agents earned fees
medium
Request responses and validations can be mocked leading to extraction of fees and/or forcing other generators to lose their fees by making them outliers
medium
Phase calculation inaccuracy will always extend sell phase and cut withdrawal phase time
low
high
high
high
high
medium
high
medium
Sep '24
high
high
medium