
Payouts

Top 10

Top 25

Top 50
All
Cantina
CodeHawks
Aug '25
high
medium
May '25
medium
high
high
high
medium
Feb '25
high
RAACNFT mint function receives funds to address(this) but has no way of withdrawing them
high
Reward manipulation vulnerability in StabilityPool
high
Users can borrow more assets than they have deposited as collateral
high
NFTs Get Permanently Locked in Stability Pool After Liquidation
high
Any attempt to liquidate a user will fail, because StabilityPool does not hold crvUSD during operational lifecycle
high
Double Usage Index Scaling in StabilityPool Liquidation Inflates Required CRVUSD Balance
high
Untracked Direct Fee Transfers from RAACToken to FeeCollector Break Fee Distribution System
medium
RToken.transferFrom() Does Not Scale User Balances Due to Stale Liquidity Index
medium
Users Can Lose Funds and Collateral by Repaying Loans After Liquidation Grace Period Expiry
medium
There is no logic checking for RAACNFT price staleness before minting it
medium
Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations
medium
Liquidations are enabled when repayments are disabled, causing borrowers to lose funds without a chance to repay
medium
Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator
medium
Multiple Token Management Lets Withdraw a Token Different than Deposited Token
medium
Flawed Boost Multiplier Calculation Always Yields Maximum Boost
medium
balanceOf(address(this)) in StabilityPool causes reward distribution to be higher than it should be
medium
The earned yield from the Curve vault can never be utilized when withdrawing or borrowing
medium
closeLiquidation within LendingPool does not allow partial repayments, which can cause massive losses to users within edge case
low
Incorrect Timestamp Tracking in RAACHousePrice contract
Jan '25
Dec '24