Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
Mar '25
high
Missing authorization check in `Payment::payWithERC20()` allows unauthorized token transfers
medium
Missing worker deployment timeout mechanism leads to permanently stuck deployments
medium
Missing signature invalidation in `BlueprintCore::updateWorkerDeploymentConfigWithSig()` allows token balance draining and configuration update replay
medium
Incomplete whitelist implementation in `BlueprintCore` allows bypass of agent creation restrictions
high
Feb '25
Jan '25
high
high
high
high
high
high
medium
May '23
Sep '21
Aug '21
Jul '21