Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
Cantina
CodeHawks
Mar '25
Jan '25
high
Market rate of bondETH is wrongly used during redeeming levETH
medium
Failed auctions lead to coupon distribution DoS
medium
BondETH redemption will revert with underflow if TVL is less than redemption value
medium
Automatic pool selection in BondOracleAdapter may cause it to report an incorrect price
medium
Bidding may be blocked if a previous bidder is blacklisted by USDC
medium
Users can manipulate pool reserve balance to end auction in their favor
Findings not publicly available for private contests.
medium
Dec '24
medium
high
Anyone can create StopLimit orders on behalf of users with existing approvals
high
User may lose funds if several orders created in the same block
high
An attacker can drain contract funds by calling modifyOrder on fulfilled or cancelled orders
high
Attacker can drain contract via reentrancy in OracleLess.fillOrder
medium
An attacker can DoS pending orders queue
medium
OracleLess Vulnerable to DoS via Order Flooding
Nov '24
high
ReputationMarket contract can become insolvent due to wrong fee accounting
high
Buyers lose a portion of remaining ETH due to wrong fees calculation
high
Author can avoid portion of fees due to donation rewards distribution flaw
high
Market liquidity can be drained due to inefficient pricing formula
medium
No slippage protection in `ReputationMarket.sellVotes()`
Oct '24
high
Subtraction in `variance()` will revert due to underflow
high
Potential underflow vulnerability in score range calculation of `LLMOracleCoordinator::finalizeValidation`, leading to DoS.
medium
Request responses and validations can be mocked leading to extraction of fees and/or forcing other generators to lose their fees by making them outliers
medium
Unrestricted validation score range for validators in `LLMOracleCoordinator::validate`.
medium
BuyerAgent Batch Purchase Failure Due to Asset Transfer or Approval Revocation
low
Sequential Fee Calculations Lead to Lost Platform Revenue Due to Precision Loss
Sep '24
Aug '24
Jul '24
Mar '24
Feb '24
Jan '24