Payouts
3rd Places
Top 10
Top 25
All
Code4rena
Aug '22
high
Builder can call `Community.escrow` again to reduce debt further using same signatures
high
Builder can halve the interest paid to a community owner due to arithmetic rounding
high
Project funds can be drained by reusing signatures, in some cases
medium
Attacker can drain all the projects within minutes, if admin account has been exposed
medium
Missing upper limit definition in replaceLenderFee() of HomeFi.sol
Jul '22
high
Proposer can `start` a perpetual buyout which can only `end` if the auction succeeds and is not rejected
medium
An attacker can DoS vault's buyout with as little as 1 wei per 4 days
medium
Delegate call in `Vault#_execute` can alter Vault's ownership
medium
Use of `payable.transfer()` may lock user funds
Jun '22
May '22
Apr '22
Mar '22