Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Jan '23
high
Use safeTransfer/safeTransferFrom consistently instead of transfer/transferFrom
high
Debt token is transferred to zero address instead of lender when borrower repay full amount
high
Lender can reject receiving repayment through token hook, making the loan defaulted
medium
Loan can have a very long duration because rollable is True by default
Dec '22
high
Hijacking of node operators minipool causes loss of staked funds
high
AVAX Assigned High Water is updated incorrectly
medium
MinipoolManager: recordStakingError function does not decrease minipoolCount leading to too high GGP rewards for staker
medium
slashing fails when node operator doesn't have enough staked `GGP`
medium
Cancellation of minipool may skip MinipoolCancelMoratoriumSeconds checking if it was cancelled before
medium
State Transition: Minipools can be created using other operator's AVAX deposit via recreateMinipool
medium
Inflation rate can be reduce by half at most if it get called every 1.99 interval.
medium
NodeOp funds may be trapped by a invalid state transition
Nov '22
Oct '22
Sep '22
Aug '22
Jun '22