Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Jun '25
May '25
high
An attacker can use cross chain borrowing to drain another chain
high
Cross chain borrow functionality negelects remote chain debts
high
`_handleValidBorrowRequest` does not scale the previous borrow amount using the current index
medium
Borrow function misapplies single market borrow factor to multi market borrowed value
medium
Baddebts will continue to accrue for some underwater positions
medium
USDT tokens will be permanently stuck and unredeemable
medium
Findings not publicly available for private contests.
high
Apr '25
Findings not publicly available for private contests.
Feb '25
medium
medium
Jan '25
high
medium
medium
medium
Dec '24
high
An attacker can redeem all the usdt tokens available in the protocol for a small amount of usda
high
A malicious user can reuse a previously signed `excessProfitCumulativeValue` to steal profit.
high
`Abond_Token.sol::transferfrom` does not correctly update state
high
Logic flaw in `BorrowLib.sol::getOptionFeesTOPay` allows users to bypass the `renewOption` deadline
high
An Attacker can update `downsideProtected`
high
A malicious borrower can make their position immune to `Liquidationtype1`
medium
Profit/Loss will be wrongly updated between concecutive deposits
medium
An attacker can disrupt multisgn quorum on setter functions.
medium
`Ethvolatility` is never verified and can be abused by users
medium
Excess native token sent in `borrowing.sol::renewOptions` is not refunded and can be stolen by other users
Nov '24
high
Oct '24
Aug '24