Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Jan '25
medium
Dec '24
high
Out-of-Bounds Array Access in `_calculateQuantAMMVariance` with Odd Number of Assets and Vector Lambda
high
Fee Evasion via LP Token Transfer Resets Deposit Value
high
Loss of Fees for Router `UpliftOnlyExample` due to Division Rounding in Admin Fee Calculation, Causing Unfair Fee Distribution
high
Owner fee will be locked in `UpliftOnlyExample` contract due to incorrect recipient address in `UpliftOnlyExample::onAfterSwap`
high
GradientBasedRules will not work for >=4 assets with vector lambdas
high
fees sent to QuantAMMAdmin is stuck forever as there is no function to retrieve them
medium
“Uplift Fee” Incorrectly Falls Back to Minimum Fee Due to Integer Division
medium
Transferring deposit NFT doesn't check if the receiver exceeds the 100 deposit limit
medium
Users transferring their NFT position will retroactively get the new `upliftFeeBps`
low
Inconsistent timestamp storage when the LPNFT is transferred.
low
missing implementation for a function to change upliftFee
medium
Incorrect Total Assets Calculation in _harvestAndReport Leading to Share Value Manipulation and Irredeemable Assets
medium
not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.
medium
Inflated `totalAssets` in `StrategyMainnet`, `StrategyArb`, and `StrategyOp` Contracts
high
Cancel doesn't remove orders mappings, allowing attacker to modify it to extract funds again
high
in oracleLess, attacker can create two orders in same block to steal funds
high
cross function reentrency to cause loss of funds to user by malicious `target`
high
users that gave approvals to `stopLimit` contract can be drained
high
Attacker can use malicious token with hook in `oracleLess` to cause loss of funds to users
medium
attacker can dos the time sensetive `fillStopLimitOrder::stopLimit`
medium
wrong logical operator in `PythOracle` Forcing Stale prices only
Oct '24
Sep '24
high
relisting previously liquidated NFT will cause loss of funds to new owner
high
reserving a previously liquidated Token will cause loss of funds to new owner
high
`Listings::reserve()` doesn't delete reserved listings causing integration issue
high
Voters lose their tokens due to misconfiguration in `cancel` function
high
Malicious Whale can cause Loss of Fees of LP Providers
high
User Initializing a Pool will have his funds stuck
high
Owner of Bridged ERC1155 Royalties can't claim them
high
Attacker can frontrun large fee deposits from `fillListing`
medium
Malicious user can prevent `lockerManager` from executing `CollectionShutdown` function
medium
Malicious user can bypass execution of `CollectionShutdown` function
medium
EdgeCase in `CollectionShutdown` leading to funds being stuck.
medium
Malicious Whale can manipulate `totalsupply` to liquidate or illiquidate a liqudiateable listing
medium
Broken core contract functionality `UniswapImplementation::setFeeExemption` making `exemptionFee` is never useable
medium
User extra funds during Pool initializtion would be stuck in `UniswapImplementation`
Aug '24
Jul '24