Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
CodeHawks
Jul '24
May '24
Mar '24
Feb '24
Jan '24
Dec '23
Oct '23
Sep '23
Aug '23
low
If a winner is blacklisted on any of the tokens they can't receive their funds
low
Centralization Risk for trusted organizers
low
Organizers are not incentivized to deploy and distribute to winners causing that winners may not to be rewarded for a long time and force the protocol owner to manage the distribution
Jul '23
high
Borrower can bypass maxLoanRatio's configuration of a pool via buyLoan()
high
[H-04] Lender#buyLoan - Malicious user could take over a loan for free without having a pool because of wrong access control
high
Attacker can steal a loan's collateral and break the protocol
low
Zero address leads to transaction reverts
low
Lender fails to giveLoan because of inconsistent length between `loadIds` and `poolIds`
low
Missing Events Emitting
gas
No use of Ownable in Staking contract.
gas
Use do while loops instead of for loops.
gas
MaxLoanRatio is not configured properly.
5.30 USDC • 4 total findings • CodeHawks • 0xsandy
#92