High
Total
Medium
Solo
Total
$74.64K

Total Earnings
#111 All Time

9x
Payouts

3x
2nd Places

2x
3rd Places

7x
Top 10
All
Sherlock
Code4rena
Feb '23
Findings not publicly available for private contests.
high
Protection buyer loses protection if NFT is transferred or split
high
Protection buyer may buy multiple protections for same goldfinch NFT
high
Dos due to unbounded array of active protections may prevent locking of capital
high
Seller may bypass the 2 cycles safeguard after initial 2 cycles
high
Sybil on withdrawal requests can allow leverage factor manipulation with flashloans
medium
Freezing of the protocol when totalSTokenUnderlying is zero but totalSupply is non-zero
medium
Growing of totalSupply after successive lock/unlockCapital can freeze protection pools by uint overflow
high
Token might become unrefundable because of arithmetic overflow in `getLockedFunds`
high
Number of deposits can increase infinitely and prevent any refund
high
A rogue deposited ERC-20 token can break the payouts
medium
Resizing the payout schedule with less items might revert
medium
DoS on NFT deposit due to deposit limit
Jan '23
Dec '22
Findings not publicly available for private contests.
Nov '22
high
In some cases a hundred tokens is a too large value to use for pricing liquidity
high
isoUSDLoaned used instead of isoUSDLoanAndInterest in openLoan of Vault_Synths.sol
high
Theft of rewards in Depositor.sol
medium
priceLiquidity may revert in directional market conditions preventing legitimate liquidations
high
Incorrect accounting in SyndicateRewardsProcessor results in any LP token holder being able to steal other LP tokens holder's ETH from the fees and MEV vault.
high
Giant pools can be drained due to weak vault authenticity check
high
Any user being the first to claim rewards from GiantMevAndFeesPool can unexepectedly collect them all
high
Possibly reentrancy attacks in `_distributeETHRewardsToUserForToken` function
high
Rewards of GiantMevAndFeesPool can be locked for all users
high
Theft of ETH of free floating SLOT holders
Oct '22