Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
CodeHawks
Jul '24
Oct '23
high
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
high
Attacker can reenter to mint all the collection supply
high
Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders
medium
Auction winner can prevent payments via `safeTransferFrom` callback
Sep '23
Aug '23
Jul '23
37.94 USDC • 2 total findings • CodeHawks • talfao
#54
high
Draining funds from Rewarder / Preventing users from withdrawing from LMPVault
high
Double spending issue in LMPRouter
high
Perform liquidations function always fails.
high
Loss rewards from Destination Vault rewarder due to positive slippage and other conditions
high
Double scaling of price filters in IncentivePricingStats.sol
medium
LMPVault is not entirely compliant with the ERC4626 standard.