Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
CodeHawks
Jan '25
Dec '24
high
Accounting error in `Abond_Token::transferFrom` leads to broken functionality and loss of funds
high
Lack of input validation in `borrowing::redeemYields` allows anyone to redeem abond tokens as per someone else's `ethBacked` abond state
high
Re-usable signatures can lead to loss of funds.
high
Lack of expiry in signatures can lead to hoarding signatures for a profitable `CDS:withdraw` in future
high
Users can renew options at any time
medium
Malicious actor can DoS admin functions due to lack of access control
medium
Stale `lastEthprice` used in `borrowing::depositTokens` will artificially inflate/deflate the ratio
medium
Protected downside is not updated when `cds.getTotalCdsDepositedAmount() < downsideProtected`
Nov '24
medium
Attacker can deny lend order cancellation for others leading to loss of funds.
medium
Improper handling of token order in `MixOracle.sol` will lead to bricked/incorrect price feed.
medium
Malicious actor can match his own lend and borrow order using a flash loan to inflate incentives at end of epoch.
Oct '24
high
Subtraction in `variance()` will revert due to underflow
medium
Request responses and validations can be mocked leading to extraction of fees and/or forcing other generators to lose their fees by making them outliers
medium
Unrestricted validation score range for validators in `LLMOracleCoordinator::validate`.
medium
Users can list assets with price < 1 ERC20 (ETH, WETH), leading to potential DoS vulnerability.
low
Incorrect Proof-of-Work Difficulty Check in `assertValidNonce` Function
high
medium
Sep '24
Aug '24
Feb '24