Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Jan '24
high
Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale
high
Unauthorized Access to setCurves Function
medium
Protocol and referral fee would be permanently stuck in the Curves contract when selling a token
medium
onBalanceChange causes previously unclaimed rewards to be cleared
medium
If a user sets their curve token symbol as the default one plus the next token counter instance it will render the whole default naming functionality obsolete
May '23
Apr '23
high
Missing access control on `commitCollateral` allows any malicious user to transfer the borrower many tokens and commit them as collateral to DoS a bid's acceptance
high
Borrower can front-run lenderAcceptBid to modify collateral amounts or IDs
medium
A malicious market owner who is also a lender can manipulate fees to accept a bid where the borrower does not receive any principal
medium
Market owners can setBidExpirationTime to a value that will not allow any bid to be accepted
Mar '23