Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
CodeHawks
Feb '25
Oct '24
Aug '24
Jul '24
Jun '24
71.22 USDC • 1 total finding • Sherlock • yotov721
#14
May '24
Mar '24
Feb '24
high
Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win
high
Since you can reroll with a different fighterType than the NFT you own, you can reroll bypassing maxRerollsAllowed and reroll attributes based on a different fighterType
high
Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes
high
FighterFarm:: reroll won't work for nft id greator than 255 due to input limited to uint8
medium
NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)
medium
Can mint NFT with the desired attributes by reverting transaction
medium
Fighter created by mintFromMergingPool can have arbitrary weight and element