Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Feb '25
Jan '25
Dec '24
high
A malicious user can use other user's signature when withdraw from `CDS`.
high
Attacker can steal all usdt from treasury through `CDS.sol#redeemUSDT()`.
high
An attacker can freeze CDS.
high
An attacker can increase `borrowing.lastCumulativeRate` much bigger without limit causing freeze of borrowing.
high
An attacker can steal funds from treasury.
high
The owner cannot withdraw the interest from liquidation.
high
Admin will lose `eth` or can be not able to liquidate unhealthy position.
medium
An attacker can manipulate `omniChainData.cdsPoolValue` by breaking protocol.
medium
The `borrowing.lastCumulateRate` is updated wrongly when withdrawal from borrowing.
medium
Wrong applying of `lastCumulativeRate` can lead to increasing of borrower's debt or decreasing borrower's repay amount, unexpectedly.
Oct '24
Sep '24