Payouts
3rd Places
Top 10
Top 25
All
Sherlock
CodeHawks
Jan '25
high
Incorrect Redemption Rate Applied to Leverage Tokens Due to Unconstrained Market Rate Check
high
Incorrect period used in `transferReserveToAuction` leads to complete failure of action system and loss of bidders' funds.
medium
USDC blacklist will permanently DOS the Auction contract affecting all users
medium
Users will receive incorrect redemption amounts due to decimal normalization error in market rate calculation
Dec '24
high
Fee Evasion via LP Token Transfer Resets Deposit Value
medium
quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.
medium
Wrong Fee Take Function Called in UpliftOnlyExample Causing Incorrect Fee Distribution
low
Inconsistent timestamp storage when the LPNFT is transferred.
Sep '24
Aug '24
high
Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function
high
Native token withdrawal fails until manually approved
high
Malicious user can drain protocol by bypassing `ASK` offer abortion validation in `Turbo` mode
high
Token withdrawal fails until someone manually approves spending
low
[Low-01] Missing Access Control in `CapitalPool::approve()` Function Allows any User to call it to set Allowance Amount `TokenContract` to `type(uint256).max`.
low
3 `OfferStatus` are never used, and code seems to have contradicting intentions