Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
CodeHawks
Mar '24
Sep '23
Aug '23
Jul '23
high
Sandwich attack to steal all ERC-20 tokens in the Fees contract
high
[H-04] Lender#buyLoan - Malicious user could take over a loan for free without having a pool because of wrong access control
high
Using forged/fake lending pools to steal any loan opening for auction
high
Attacker can steal a loan's collateral and break the protocol
high
Lender can Sandwich a borrower to seize his collateral
medium
The `borrow` and `refinance` functions can be front-run by the pool lender to set high interest rates
medium
No expiration deadline leads to losing a lot of funds
medium
Single-step process for critical ownership transfer is risky
medium
Fixed fee level is used when swap tokens on Uniswap
medium
Some ERC20 tokens would revert on zero value fee transfers.
low
Operator can prevent customers from borrowing from a given pool
gas
Don't use draft versions in production
Jun '23
May '23
high
Lack of proper access control in `mintRebalancer` and `burnRebalancer` functions
high
Incorrect decimals handling for DAI/ETH price feed
high
Missing deadline check and hardcoded slippage in `UniV3SwapInput` function
high
The rebalancing decisions are based on manipulable spot price
medium
Minting exposes users to unlimited slippage
medium
Chainlink oracle return values are not handled properly
Apr '23