Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Jul '24
Jan '24
Nov '23
Oct '23
high
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
high
Attacker can reenter to mint all the collection supply
high
Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders
medium
The RandomizerVRF and RandomizerRNG not produce hash value.
medium
Auction winner can prevent payments via `safeTransferFrom` callback