Payouts
Top 25
Top 50
All
Sherlock
Code4rena
CodeHawks
Jul '25
Mar '25
Feb '25
high
RAACNFT mint function receives funds to address(this) but has no way of withdrawing them
high
Incorrect Reward Claim Logic in FeeCollector::claimRewards Causes Denial of Service
high
Boost Miscalculation Leads to Excess Distribution
medium
Incorrect accounting in `veRAACToken::emergencyWithdraw` and `veRAACToken::withdraw` due to missing `totalLocked` update
medium
Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations
medium
Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations
medium
hardcoded baseamount in Updateuserboost fucntion causes users with small token holdings to receive higher boosts relative to their holdings t
medium
Multiple Token Management Lets Withdraw a Token Different than Deposited Token
medium
Users Cannot Remove Their Own Boost Delegation, Causing Potential Lock-In
low
Lack of enforcement of the `MAX_TOTAL_LOCKED_AMOUNT`
low
Incorrect Initialization of minBoost in BaseGauge Constructor Breaks Core Contract Functionality
low
`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types
low
Overwriting Previous Allocations in allocateFunds May Lead to Loss of Cumulative Allocation Data
low
Insufficient ETH Forwarding in Governance Execution Mechanism Causes Proposal Failures