
Payouts

Top 25

Top 50
All
Sherlock
Nov '25
high
`removeTokenIdAtIndex` lets owner remove active staking NFTs from accounting to mint underpriced shares and drain the vault
medium
Duplicate tranche entries let owner over-withdraw vault assets
medium
`stNXM::extendDeposit` removes stake from accounting
medium
Uniswap TWAP oracle bricks Morpho market when pool keeps default observation cardinality
Oct '25
Sep '25
high
`FeeWalker::up` will undercalculate `compoundingLiq` by a factor of `key.width()` for all unvisited nodes
high
Inconsistent high tick exclusivity between `WalkerLib::modify` and `PoolWalker::settle` resulting in inconsistent updates and settles
medium
`TimedAdmin` implemented in `Diamond` is broken for `acceptOwnership` resulting in ownership not being able to be transferred
medium
`NFTManager::_generateMetadata` and `NFTManager::_generateSVG` retrieves asset data from NFTManager storage instead of Diamond storage resulting in DoS of `NFTManager::tokenURI` calls
Mar '25