
Payouts

1st Places

3rd Places

Top 10
All
Sherlock
Code4rena
Cantina
Jan '26
high
UniswapPriceOracle.validatePrice() TWAP Calculation Flaw
high
Variable Overwrite in checkPoolAndGetCenterPrice() Creates Dead-Code Deviation Check, Leaving All V3 Protocol-Owned Liquidity Operations Unprotected
medium
Services can earn undeserved rewards by manipulating checkpoint timing during reward droughts
medium
Balancer oracle deadlock from cumulative price weight
medium
Uniswap oracle validateprice can be griefed per block via `sync()`
Dec '25
high
BuilderWallet `init()` is unprotected/re-initializable, enabling takeover and theft of builder fees
medium
Self-settlement via `dispatchFrom` bypasses refund mechanism allowing underfunded debt settlement
medium
Withdrawing just before a bad debt event can increase losses for remaining liquidity providers
medium
`dispatchFrom()` Liveness DoS via `StaleOracle`: Spot Price Manipulation Blocks Liquidations, Force Exercises, and Premium Settlements
medium
Commission Share-Burn Distribution is JIT-Capturable When `builderCode == 0` (Default)
Nov '25
medium
Duplicate tranche tracking enables share-price inflation and owner withdrawal abuse.
medium
Missing tranche update in extendDeposit causes underpriced shares.
medium
Uniswap V3 liquidity operations lack slippage protection
medium
Oracle APY sanity check weakens over time and stops protecting against price manipulation
Oct '25
medium
medium
medium
medium
medium
Sep '25
Jul '25
Mar '25
Feb '25
high
medium
Jan '25
Feb '24