Payouts
Top 10
Top 25
Top 50
All
Sherlock
Cantina
CodeHawks
Feb '24
high
high
high
medium
Jul '23
high
Sandwich attack to steal all ERC-20 tokens in the Fees contract
high
Borrower can use Refinance to cancel auctions so they can extend their loan indefinitely
high
During refinance() new Pool balance debt is subtracted twice
high
[H-04] Lender#buyLoan - Malicious user could take over a loan for free without having a pool because of wrong access control
high
Using forged/fake lending pools to steal any loan opening for auction
high
Stealing any loan opening for auction through others' lending pool
high
Token spending by Uniswap router doesn't get approved
high
A pool lender can fully drain another user's pool by abusing `buyLoan`
medium
Lender contract can be drained by re-entrancy in `refinance` (collateral)
gas
Save gas for collecting protocol fees and interests
gas
Lack of pause pool function in Lender contract
Jun '23
May '23