TW
Tripwire
Find contracts. Test them. Review real vulns.
Confirmed Findings
2,205
crit 60 high 1157
All Findings
46,184
Across all runs
Chain
1
Mainnet focus
Signal Mix
24239
high severity in results
Findings
filter + triage
Reset
Severity Tool Title Address Value USD Validated Confirmed Found Run
high codex Uninitialized lastFeeTime causes excessive management fees and can brick first settlement 0xe50554ec802375c9c3f9c087a8a7bb8c26d3dedf $0.00 no 3 months ago 42f21ca1-82d3-426a-a45a-788b3a4f9d5b
high codex Hardcoded privileged borrow bypasses Comptroller risk checks 0x2ac63723a576f89b628d514ff671300801dc1702 $0.00 no 3 months ago a66a7849-282c-405c-94d3-afe6d6d3f5a1
high codex Unprotected initialize allows hostile setup of critical bridge addresses 0xe80b4e0ed5e92d865f4708eee0e1564287a7d848 $0.00 no 3 months ago e9597aef-e9cc-49ba-9d81-2312231691b5
high codex LP share accounting ignores trader PnL and vault asset flows, enabling over-redemption 0xe3d41d19564922c9952f692c5dd0563030f5f2ef $21,609,903.28 no 3 months ago dc08fc38-6d54-4fb0-8a86-bb65f82abb39
high codex Unrestricted initialization of tap allows attacker-controlled liquidator 0x448a5065aebb8e423f0896e6c5d525c040f59af3 $20,792,403.90 no 3 months ago a07440d4-9742-4482-9bb0-05239d80eb1f
high codex `setup` is externally callable via proxy with no one-time initializer guard 0x99b5fa03a5ea4315725c43346e55a6a6fbd94098 $0.00 no 3 months ago 8a7c4282-fe4b-4a35-b94c-7694cbef39ea
high codex Unprotected one-time admin initialization can be front‑run 0x1681195c176239ac5e72d9aebacf5b2492e0c4ee $34,620,088.63 no 3 months ago 2d583407-2d3a-41a0-85ac-6f1a8195edd9
high codex Unprotected tap assignment allows attacker to seize liquidation/tax flows 0xbda109309f9fafa6dd6a9cb9f1df4085b27ee8ef $43,734,589.13 no 3 months ago f58f1e0d-d765-4f42-8774-1b1e4abc5a43
high codex Chainlink oracle responses are not validated for negative/stale data 0x6fcbbb527fb2954bed2b224a5bb7c23c5aeeb6e1 $266,056.63 no 3 months ago 019b426d-be82-7158-aec7-2fbd5b8cb931
high codex Gateway-controlled delegatecall enables arbitrary code execution in Agent context 0xd803472c47a87d7b63e888de53f03b4191b846a8 $7,165,862.10 no 3 months ago 019b422c-5600-71b9-95ab-04ba54ca9f3f