High
Solo
Total
Medium
Solo
Total
Total Earnings
#83 All Time
Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
Cantina
Jan '25
high
high
high
high
high
high
high
high
medium
Findings not publicly available for private contests.
Dec '24
high
high
high
high
high
high
medium
medium
medium
medium
medium
Oct '24
high
high
high
high
high
high
medium
medium
medium
medium
medium
medium
medium
Sep '24
high
high
high
high
high
high
high
medium
medium
medium
medium
medium
Jul '24
high
Single plot can be occupied by multiple renters
high
Failure to Update Dirty Flag in transferToUnoccupiedPlot Prevents Reward Accumulation On Valid Plot
high
[H-01] Miscalculation in `_farmPlots` function could lead to a user unable to unstake all NFTs
medium
Users can farm on zero-tax land if the landlord locked tokens before the LandManager deployment
Jun '24
Findings not publicly available for private contests.
Apr '24
high
First Depositor Attack
medium
Bad debt isn't cleared when `earningsAccumulator` is lower than a fixed-pool bad debt
medium
Fixed interest rates can be manipulated by a whale borrower
medium
Theft of unassigned earnings from a fixed pool
medium
DoS on liquidations when utilization rate is high
medium
Manipulation of the floating debt by updating `floatingBackupBorrowed`
Mar '24
Feb '24
Jan '24
high
Permanent lock of all funds when the funding fees are bigger than total margin
high
Attacker can steal funds due to settling PnL with wrong price on a liquidation
high
Users can avoid paying trade fees on limit orders
high
Inability to Liquidate Certain Positions Due to Erroneous Stable Collateral Update
medium
First Depositor of Stable Collateral will cause a System-Wide Denial of Service
medium
Users Can Exceed Maximum Skew Due to Unsettled PnL
high
Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale
high
Unrestricted claiming of fees due to missing balance updates in `FeeSplitter`
high
Unauthorized Access to setCurves Function
medium
Protocol and referral fee would be permanently stuck in the Curves contract when selling a token
medium
onBalanceChange causes previously unclaimed rewards to be cleared
medium
Withdrawing with amount = 0 will forcefully set name and symbol to default and disable some functions for token subject
medium
Theft of holder fees when `holderFeePercent` was positive and is set to zero
Dec '23
high
The userGaugeProfitIndex is not set correctly, allowing an attacker to receive rewards without waiting
high
Users staking via the `SurplusGuildMinter` can be immediately slashed when staking into a gauge that had previously incurred a loss
medium
Wrong ProfitManager in GuildToken, will always revert for other types of gauges leading to bad debt
medium
`totalBorrowedCredit` can revert, breaking gauges.
medium
Inability to offboard term twice in a 7-day period may lead to bad debt to the market
medium
Incorrect calculations in debtCeiling
medium
LendingTerm::debtCeiling() can return wrong debt as the min() is evaluated incorrectly
Oct '23
Sep '23
May '23
Apr '23
Mar '23