Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Nov '24
Collaborative Audit • Sherlock • windhustler
Apr '24
Jan '24
Nov '23
Collaborative Audit • Sherlock • windhustler
Oct '23
Sep '23
Aug '23
Jul '23
high
Refund mechanism for failed cross-chain transactions does not work
high
Attacker can block LayerZero channel due to missing check of minimum gas passed
high
Attacker can block LayerZero channel due to variable gas cost of saving payload
high
TOFT `triggerSendFrom` can be used to steal all the balance
high
TOFT `removeCollateral` can be used to steal all the balance
high
TOFT `exerciseOption` can be used to steal all underlying erc20 tokens
high
TOFT leverageDown always fails if TOFT is a wrapper for native tokens
medium
TOFT `exerciseOption` fails due to not passing `msg.value` properly
medium
Airdropped tokens can be stolen by a bot
Apr '22