Payouts
1st Places
2nd Places
Top 10
All
Sherlock
Code4rena
Cantina
CodeHawks
Jan '25
high
medium
medium
medium
medium
medium
high
medium
medium
Dec '24
high
high
high
high
high
high
medium
medium
medium
medium
Nov '24
high
Oct '24
high
high
high
high
high
medium
medium
medium
medium
medium
medium
medium
medium
Sep '24
high
high
high
high
high
medium
Aug '24
high
Reentrancy Vulnerability Allows Bypass of Cooldown, Leading to Unfair Reward Extraction Through Flash Loan
high
Exposed `_removeCredIdPerAddress` & `_addCredIdPerAddress` allows anyone to cause issues to current holders as well as upcoming ones
high
`shareBalance` bloating eventually blocks curator rewards distribution
high
Signature replay in `createArt` allows to impersonate artist and steal royalties
medium
`PhiFactory:claim` Potentially Causing Loss of Funds If `mintFee` Changed Beforehand
medium
Attacker can DOS user from selling shares of a credId
medium
Lack of data validation when users are claiming their art allows malicious user to bypass signature/merkle hash to provide unapproved `ref_`, `artId_` and `imageURI`
Jul '24
high
`vestTokens` bug in MultiFeeDistribution.sol causes new incentives to erase previous incentives
medium
bug in `claim` allows users who are disqualified to claim their previously earned emissions
medium
Rewards may be spread out among the **wrong time period** due to the way the protocol calculates it
medium
`lastRPS` could be set to `0` accidentally
medium
Users of a vault can steal other user's rewards when one vault's `lastRewardTime` differs from another vault's `lastRewardTime`
Jun '24