|
high
|
detector |
Untrusted CALL target/value reachable |
0x15c5f0f18feb8a9f5808ccd2fc4ac279d9d89bb8
|
$46,200.14 |
no
|
no
|
2 months ago
|
019c0ea9-06d5-7319-83a0-bdeeddb23af3
|
|
high
|
codex |
Computed DELEGATECALL target reachable (arbitrary code execution risk) |
0x62c9e5e52351e02635f48072fa20c03bb650f787
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d9-53a8-71a4-b1a8-306d54433492
|
|
high
|
codex |
MF_ONE valuation uses unvalidated oracle price for share minting and TVL |
0x71ea0eb2605bd63fe69012a60c75bdbd22e8b3d3
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d8-dab2-7125-9844-e6c896367631
|
|
high
|
codex |
Relayer can finalize arbitrary transfers without on-chain validation |
0xc973d09e51a20c9ab0214c439e4b34dbac52ad67
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d7-52ed-7231-975b-72409c137e98
|
|
high
|
codex |
Unprotected initializer allows takeover of uninitialized proxy/clone |
0x387a294a2b92387cf46714faa537f1f81d50c210
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d6-c7d2-72ca-99c8-428dc13e465f
|
|
high
|
codex |
Intervals claimed only incremented by 1 enables repeated over-claims |
0x6097a40e38fa1aeea072babfaadea1f513e970a8
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d6-b2a2-72f8-8ed2-aa2958ed78a5
|
|
high
|
codex |
Spot Uniswap reserves used as price oracle enable manipulation of collateral and liquidations |
0xe3fef783783f97c7647c1f108d1c561e5ec13f92
|
$46,280.85 |
no
|
—
|
2 months ago
|
019be3d6-8551-7286-84a9-a94929610231
|
|
high
|
codex |
Computed DELEGATECALL targets enable arbitrary code execution if attacker-influenced |
0x10314a9f673476f313a598778fea9cb694856500
|
$46,500.00 |
no
|
—
|
2 months ago
|
019be3d6-8525-715e-9ddd-0261e6dd9327
|
|
high
|
slither |
Reentrancy in Cn_Bank.Collect(uint256) (contracts/Contract.sol#10-19): |
0xd84d16fc96cc69a21199454ed615c8bc66fb4026
|
$46,503.83 |
no
|
—
|
2 months ago
|
019be3d6-84e5-71ba-9f6c-009acf5f51d8
|
|
high
|
codex |
Reentrancy in Collect allows draining more than balance |
0xd84d16fc96cc69a21199454ed615c8bc66fb4026
|
$46,503.83 |
no
|
—
|
2 months ago
|
019be3d6-84e5-71ba-9f6c-009acf5f51d8
|
|
high
|
slither |
Reentrancy in Wallet.execute(address,uint256,bytes) (contracts/Contract.sol#292-296): |
0x3792d288d9f0993971f23e4758acb719f285f6ef
|
$46,511.07 |
no
|
—
|
2 months ago
|
019be3d6-84db-708f-a189-cf52464f8961
|
|
high
|
slither |
Reentrancy in Wallet.confirm(bytes32) (contracts/Contract.sol#301-308): |
0x3792d288d9f0993971f23e4758acb719f285f6ef
|
$46,511.07 |
no
|
—
|
2 months ago
|
019be3d6-84db-708f-a189-cf52464f8961
|
|
high
|
detector |
ETH value transfer possible |
0x62c9e5e52351e02635f48072fa20c03bb650f787
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d9-53a8-71a4-b1a8-306d54433492
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x62c9e5e52351e02635f48072fa20c03bb650f787
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d9-53a8-71a4-b1a8-306d54433492
|
|
high
|
codex |
SELFDESTRUCT sends funds to CALLER |
0x30689375f7ae75fb85d3a9cb7058ff231dd9f91c
|
$46,862.02 |
no
|
—
|
2 months ago
|
019be3d6-8492-73c8-8ec4-edb49b23a550
|
|
high
|
slither |
Reentrancy in TimelockController.execute(address,uint256,bytes,bytes32,bytes32) (contracts/Contract.sol#1437-1448): |
0x528fb7f75384ec26c1a65c088b637f0d1bf35702
|
$46,873.00 |
no
|
—
|
2 months ago
|
019be3d6-8489-7000-bd40-224825ebd461
|
|
high
|
slither |
Reentrancy in TimelockController.executeBatch(address[],uint256[],bytes[],bytes32,bytes32) (contracts/Contract.sol#1458-1483): |
0x528fb7f75384ec26c1a65c088b637f0d1bf35702
|
$46,873.00 |
no
|
—
|
2 months ago
|
019be3d6-8489-7000-bd40-224825ebd461
|
|
high
|
slither |
TimelockController._execute(address,uint256,bytes) (contracts/Contract.sol#1485-1491) sends eth to arbitrary user |
0x528fb7f75384ec26c1a65c088b637f0d1bf35702
|
$46,873.00 |
no
|
—
|
2 months ago
|
019be3d6-8489-7000-bd40-224825ebd461
|
|
high
|
slither |
PharaGoddess._withdraw(address,uint256) (contracts/Contract.sol#2005-2007) sends eth to arbitrary user |
0x147aa9ada01b70c4c8c8b89b06afe767908aced7
|
$46,931.90 |
no
|
—
|
2 months ago
|
019be3d6-8480-72cd-9e22-b654093a3ebf
|
|
high
|
slither |
Reentrancy in PharaGoddess.withdrawFund() (contracts/Contract.sol#1996-2004): |
0x147aa9ada01b70c4c8c8b89b06afe767908aced7
|
$46,931.90 |
no
|
—
|
2 months ago
|
019be3d6-8480-72cd-9e22-b654093a3ebf
|
|
high
|
codex |
Royalty accounting lets newly minted tokens claim past rewards |
0x147aa9ada01b70c4c8c8b89b06afe767908aced7
|
$46,931.90 |
no
|
—
|
2 months ago
|
019be3d6-8480-72cd-9e22-b654093a3ebf
|
|
high
|
slither |
SablierFlowState._streams (src/abstracts/SablierFlowState.sol#32) is never initialized. It is used in: |
0x7a86d3e6894f9c5b5f25ffbdaae658cfc7569623
|
$46,956.22 |
no
|
—
|
2 months ago
|
019be3d6-8451-73ae-9304-bf01aa16f7fb
|
|
high
|
slither |
SablierFlowState.aggregateAmount (src/abstracts/SablierFlowState.sol#20) is never initialized. It is used in: |
0x7a86d3e6894f9c5b5f25ffbdaae658cfc7569623
|
$46,956.22 |
no
|
—
|
2 months ago
|
019be3d6-8451-73ae-9304-bf01aa16f7fb
|
|
high
|
slither |
Batch.batch(bytes[]) (node_modules/@sablier/evm-utils/src/Batch.sol#13-34) has delegatecall inside a loop in a payable function: (success,result) = address(this).delegatecall(ca... |
0x7a86d3e6894f9c5b5f25ffbdaae658cfc7569623
|
$46,956.22 |
no
|
—
|
2 months ago
|
019be3d6-8451-73ae-9304-bf01aa16f7fb
|
|
high
|
slither |
Comptrollerable.transferFeesToComptroller() (node_modules/@sablier/evm-utils/src/Comptrollerable.sol#62-74) sends eth to arbitrary user |
0x7a86d3e6894f9c5b5f25ffbdaae658cfc7569623
|
$46,956.22 |
no
|
—
|
2 months ago
|
019be3d6-8451-73ae-9304-bf01aa16f7fb
|
|
high
|
detector |
Untrusted DELEGATECALL target reachable |
0x71ea0eb2605bd63fe69012a60c75bdbd22e8b3d3
|
$0.00 |
yes
|
yes
|
2 months ago
|
019be3d8-dab2-7125-9844-e6c896367631
|
|
high
|
detector |
Authorization based on tx.origin |
0x71ea0eb2605bd63fe69012a60c75bdbd22e8b3d3
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d8-dab2-7125-9844-e6c896367631
|
|
high
|
detector |
Authorization based on tx.origin |
0xa0d828a754961ff78e733701eb98d22084db242c
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d8-bb60-7023-94d5-bc2e86082ed0
|
|
high
|
slither |
Stock._sell(address,uint256) (contracts/Stock.sol#111-150) sends eth to arbitrary user |
0x1123f22a0c120d07cd660759839ae746c7a778ff
|
$47,299.28 |
no
|
—
|
2 months ago
|
019be3d6-83e1-7166-b811-d5bbdcacd0d9
|
|
high
|
codex |
Authorization based on tx.origin |
0xabfec10802e69a5d63ec954bf16a9bdafb4590b9
|
$47,366.70 |
no
|
—
|
2 months ago
|
019be3d6-83d0-7125-a47e-4da78d411734
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0xe7b6dafe6e5e3d6f7fa3ed7624633e4518b1bc54
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d8-41e3-70e9-bd84-4e12ae8f485c
|
|
high
|
detector |
ETH value transfer possible |
0xe7b6dafe6e5e3d6f7fa3ed7624633e4518b1bc54
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d8-41e3-70e9-bd84-4e12ae8f485c
|
|
high
|
detector |
Authorization based on tx.origin |
0xbdd90485fcbcac869d5b5752179815a3103d8131
|
$0.00 |
no
|
—
|
2 months ago
|
019be3d8-3ae4-7210-9784-c559a0c79016
|
|
high
|
detector |
ETH value transfer possible |
0x73d0fd329abecfbca9e0a482ed161a01616d9fca
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-f3f6-7335-be5b-07a67d5c232d
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x73d0fd329abecfbca9e0a482ed161a01616d9fca
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-f3f6-7335-be5b-07a67d5c232d
|
|
high
|
slither |
SharkPool.do_redemption() (contracts/Contract.sol#310-321) ignores return value by base_contract.transfer(msg.sender,remainder) (contracts/Contract.sol#319-320) |
0x29aa20fb9b23421e310bdb8a7cfb81d7fbb4a1b3
|
$47,924.40 |
no
|
—
|
2 months ago
|
019be3d6-8329-7283-9a66-0484d43643d5
|
|
high
|
slither |
SharkPool.do_redemption() (contracts/Contract.sol#310-321) ignores return value by base_contract.transfer(owner,owner_cut) (contracts/Contract.sol#316-317) |
0x29aa20fb9b23421e310bdb8a7cfb81d7fbb4a1b3
|
$47,924.40 |
no
|
—
|
2 months ago
|
019be3d6-8329-7283-9a66-0484d43643d5
|
|
high
|
slither |
Reentrancy in SharkPool.mine() (contracts/Contract.sol#252-288): |
0x29aa20fb9b23421e310bdb8a7cfb81d7fbb4a1b3
|
$47,924.40 |
no
|
—
|
2 months ago
|
019be3d6-8329-7283-9a66-0484d43643d5
|
|
high
|
detector |
ETH value transfer possible |
0x62c9e5e52351e02635f48072fa20c03bb650f787
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-e47d-7320-ae56-01c14905ff89
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x62c9e5e52351e02635f48072fa20c03bb650f787
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-e47d-7320-ae56-01c14905ff89
|
|
high
|
slither |
Crate.recoverETH() (contracts/crate/Crate.sol#303-308) sends eth to arbitrary user |
0x5c29376a264e9244b50076650cea0cf30172c466
|
$48,597.60 |
no
|
—
|
2 months ago
|
019be3d6-829b-7113-92ff-3299b47c7d80
|
|
high
|
slither |
Reentrancy in Crate.claimPartner(address[],string,uint256,uint8,bytes32,bytes32) (contracts/crate/Crate.sol#267-301): |
0x5c29376a264e9244b50076650cea0cf30172c466
|
$48,597.60 |
no
|
—
|
2 months ago
|
019be3d6-829b-7113-92ff-3299b47c7d80
|
|
high
|
codex |
Relayer can finalize arbitrary transfers without proof or fee verification |
0xdbf24caff1470a6d08bf2ff2c6875bafc60cf881
|
$48,695.70 |
no
|
—
|
2 months ago
|
019be3d6-828a-71dc-80f1-1fb633b503be
|
|
high
|
detector |
ETH value transfer possible |
0xc973d09e51a20c9ab0214c439e4b34dbac52ad67
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-52ed-7231-975b-72409c137e98
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0xc973d09e51a20c9ab0214c439e4b34dbac52ad67
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-52ed-7231-975b-72409c137e98
|
|
high
|
slither |
KotoV3.bondLp(uint256) (src/KotoV3.sol#161-201) ignores return value by IERC20Minimal(pair).transferFrom(msg.sender,address(BOND_DEPOSITORY),_lpAmount) (src/KotoV3.sol#164) |
0x64c7d8c8abf28daf9d441c507cfe9be678a0929c
|
$48,840.97 |
no
|
—
|
2 months ago
|
019be3d6-8267-739c-b062-5f21bd63b2eb
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x40b45c2a9b30927292db21625de50de38f577c66
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-168b-7122-9efc-7b635b193209
|
|
high
|
detector |
ETH value transfer possible |
0x40b45c2a9b30927292db21625de50de38f577c66
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d7-168b-7122-9efc-7b635b193209
|
|
high
|
slither |
ExchangeProxy.transferAll(TokenInterface,uint256) (contracts/Contract.sol#775-788) sends eth to arbitrary user |
0x3e66b66fd1d0b02fda6c811da9e0547970db2f21
|
$49,401.65 |
no
|
—
|
2 months ago
|
019be3d6-8201-73d9-b7fe-2f43c4915ca9
|
|
high
|
detector |
ETH value transfer possible |
0x387a294a2b92387cf46714faa537f1f81d50c210
|
$0.00 |
no
|
no
|
2 months ago
|
019be3d6-c7d2-72ca-99c8-428dc13e465f
|