Payouts
3rd Places
Top 10
Top 25
All
Sherlock
May '24
medium
Using deprecated interfaces `PUFFER_DEPOSITOR.depositStETH()` causes DOS
medium
Invalid check for repayAmount in `MetapoolRouter::receiveFlashLoan` cause DOS
medium
Checking `RSETH_DEPOSIT_POOL.minAmountToDeposit()` in `RsETHAdapter::_stake()` causes Dos
medium
Checking return share in `_stake()` causes Dos
Apr '24
high
Burning shares token before calculating in `burnSharesToWithdrawEarnings()` causing error result
high
Use safeTransferFrom() instead of transferFrom()
high
Checking for Collateral required in LenderCommitmentGroup_Smart::acceptFundsForAcceptBid is incorrect
high
`TellerV2::repayLoan()` can be frontrun to profit from an increase in share price
high
Missing interest when calculating Amount owed for a bid in `LenderCommitmentGroup_Smart::liquidateDefaultedLoanWithIncentive()`
high
The collateral Token is mistakenly given to the lender when the liquidator call liquidateDefaultedLoanWithIncentive()
medium
`sharesExchangeRate()` may be zero causing Users mint zero shares token in `lenderCommitmentGroupSmart.addPrincipalToCommitmentGroup()`
medium
Calling the wrong function name in `FlashRolloverLoan_G5::_acceptCommitment()` resulted in a Denial of Service (DOS)
Mar '24