
Payouts

Top 25

Top 50
All
Sherlock
Sep '25
high
Missing pool authenticity validation in `newMaker` / `adjustMaker` enables malicious “pool” to drain user funds via callback
high
Stale `asset.liq` in `adjustMaker` desynchronizes principal, leading to fee-claim DoS or unintended principal transfers
medium
src/integrations/NFTManager.sol::tokenURI reads Diamond storage from a non-Diamond contract, causing metadata DoS
medium
Incorrect Root Width Calculation Breaks Tree Mapping (Index Wrap/DoS/Accounting Corruption)
medium
Admin `transferVaultBalance` Hard-Codes User ID → Non-Functional / Migration DoS
medium
`collectFees()` refreshes timestamp for `MAKER_NC`, incorrectly re-arming JIT penalties