
Payouts

1st Places

3rd Places

Top 10
All
Sherlock
Code4rena
Cantina
Jan '26
Dec '25
high
BuilderWallet `init()` is unprotected/re-initializable, enabling takeover and theft of builder fees
medium
Self-settlement via `dispatchFrom` bypasses refund mechanism allowing underfunded debt settlement
medium
Withdrawing just before a bad debt event can increase losses for remaining liquidity providers
medium
`dispatchFrom()` Liveness DoS via `StaleOracle`: Spot Price Manipulation Blocks Liquidations, Force Exercises, and Premium Settlements
medium
Commission Share-Burn Distribution is JIT-Capturable When `builderCode == 0` (Default)
Nov '25
high
medium
medium
medium
Duplicate tranche tracking enables share-price inflation and owner withdrawal abuse.
medium
Missing tranche update in extendDeposit causes underpriced shares.
medium
Uniswap V3 liquidity operations lack slippage protection
medium
Oracle APY sanity check weakens over time and stops protecting against price manipulation
Oct '25
medium
medium
medium
medium
medium
Sep '25
Jul '25
Mar '25
Feb '25
high
medium
Jan '25
Feb '24