TW
Tripwire
Find contracts. Test them. Review real vulns.
Confirmed Findings
2,205
crit 60 high 1157
All Findings
46,184
Across all runs
Chain
1
Mainnet focus
Signal Mix
24239
high severity in results
Findings
filter + triage
Reset
Severity Tool Title Address Value USD Validated Confirmed Found Run
high slither Reentrancy in DividendPayingToken._withdrawDividendOfUser(address) (contracts/DividendPayingToken.sol#86-95): 0x456fa3183d33497b290a3d24b98ddbc902ae1da5 $57,078.35 no 3 months ago 019bab3b-ac0d-70eb-9589-3835283d1f66
low codex External ETH transfer before state update can allow reentrant double-claims 0x456fa3183d33497b290a3d24b98ddbc902ae1da5 $57,078.35 no 3 months ago 019bab3b-ac0d-70eb-9589-3835283d1f66
low codex Owner can arbitrarily change dividend shares and exclude accounts 0x456fa3183d33497b290a3d24b98ddbc902ae1da5 $57,078.35 no 3 months ago 019bab3b-ac0d-70eb-9589-3835283d1f66
low codex Fixed 3000 gas stipend can permanently lock dividends for contract wallets 0x456fa3183d33497b290a3d24b98ddbc902ae1da5 $57,078.35 no 3 months ago 019bab3b-ac0d-70eb-9589-3835283d1f66
high codex Computed-target DELEGATECALL allows code execution in caller storage if user-controlled 0x60330141cf5911c14cdb400b7ad400b3c3dfdc7a $57,113.10 no 3 months ago 019bab3b-abf8-72ed-bfa4-d886cd417463
medium codex Multiple computed-target/value CALLs may enable arbitrary external calls and ETH transfers 0x60330141cf5911c14cdb400b7ad400b3c3dfdc7a $57,113.10 no 3 months ago 019bab3b-abf8-72ed-bfa4-d886cd417463
low codex CALLCODE opcode present in runtime bytecode (reachability unclear) 0x60330141cf5911c14cdb400b7ad400b3c3dfdc7a $57,113.10 no 3 months ago 019bab3b-abf8-72ed-bfa4-d886cd417463
critical detector Untrusted DELEGATECALL target reachable 0x62c9e5e52351e02635f48072fa20c03bb650f787 $0.00 no no 3 months ago 019bab3d-a735-71f5-99d9-235223139c05
high detector Untrusted CALL target/value reachable 0x62c9e5e52351e02635f48072fa20c03bb650f787 $0.00 no no 3 months ago 019bab3d-a735-71f5-99d9-235223139c05
high detector ETH value transfer possible 0x62c9e5e52351e02635f48072fa20c03bb650f787 $0.00 no no 3 months ago 019bab3d-a735-71f5-99d9-235223139c05
medium cast DELEGATECALL present 0x62c9e5e52351e02635f48072fa20c03bb650f787 $0.00 no 3 months ago 019bab3d-a735-71f5-99d9-235223139c05
info cast Heavy CALL-family usage 0x62c9e5e52351e02635f48072fa20c03bb650f787 $0.00 no 3 months ago 019bab3d-a735-71f5-99d9-235223139c05
high slither InitializableUpgradeabilityProxy.initialize(address,bytes) (contracts/dependencies/openzeppelin/upgradeability/InitializableUpgradeabilityProxy.sol#20-28) uses delegatecall to a... 0xd35f648c3c7f17cd1ba92e5eac991e3efcd4566d $57,269.11 no 3 months ago 019bab3b-abf1-7097-9d2d-1e8607143abe
high detector Authorization based on tx.origin 0x6faee7aac498326660ac2b7207b9f67666073111 $0.00 no 3 months ago 019bab3d-a126-71a9-ba02-d6d1d782d905
medium detector CREATE/CREATE2 reachable 0x6faee7aac498326660ac2b7207b9f67666073111 $0.00 no no 3 months ago 019bab3d-a126-71a9-ba02-d6d1d782d905
medium detector Untrusted CALL target/value reachable 0x6faee7aac498326660ac2b7207b9f67666073111 $0.00 no no 3 months ago 019bab3d-a126-71a9-ba02-d6d1d782d905
medium detector ETH value transfer possible 0x6faee7aac498326660ac2b7207b9f67666073111 $0.00 no no 3 months ago 019bab3d-a126-71a9-ba02-d6d1d782d905
low cast Contract creation opcode present 0x6faee7aac498326660ac2b7207b9f67666073111 $0.00 no 3 months ago 019bab3d-a126-71a9-ba02-d6d1d782d905
info cast Heavy EXTCODE*/BALANCE usage 0x6faee7aac498326660ac2b7207b9f67666073111 $0.00 no 3 months ago 019bab3d-a126-71a9-ba02-d6d1d782d905
medium slither Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): 0x4633afa7c69379ba09912a42b7e59388af596081 $57,286.33 no 3 months ago 019bab3b-abe9-7327-9bce-fb5bae82a591
medium slither Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): 0x4633afa7c69379ba09912a42b7e59388af596081 $57,286.33 no 3 months ago 019bab3b-abe9-7327-9bce-fb5bae82a591
medium codex Unchecked ERC20 transfers in collateral/underlying payouts can break accounting and lock funds 0x98cc3bd6af1880fcfda17ac477b2f612980e5e33 $57,367.04 no 3 months ago 019bab3b-abda-71cb-bc69-892fbe7a1945
medium codex Collateralization relies on a manipulable spot oracle without freshness or sanity checks 0x98cc3bd6af1880fcfda17ac477b2f612980e5e33 $57,367.04 no 3 months ago 019bab3b-abda-71cb-bc69-892fbe7a1945
medium codex ETH oToken purchases can spend the contract’s ETH balance without enforcing msg.value 0x98cc3bd6af1880fcfda17ac477b2f612980e5e33 $57,367.04 no 3 months ago 019bab3b-abda-71cb-bc69-892fbe7a1945
high detector ETH value transfer possible 0x677ecf96dbfee1defbde8d2e905a39f73aa27b89 $0.00 no no 3 months ago 019bab3d-7dae-718a-bd33-ed21b428c9ba
high detector Untrusted CALL target/value reachable 0x677ecf96dbfee1defbde8d2e905a39f73aa27b89 $0.00 no no 3 months ago 019bab3d-7dae-718a-bd33-ed21b428c9ba
medium slither Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): 0x666ed8c2151f00e7e58b4d941f65a9df68d2245b $57,569.78 no 3 months ago 019bab3b-abc4-7372-ab15-5b46ebf8eb01
medium slither Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): 0x666ed8c2151f00e7e58b4d941f65a9df68d2245b $57,569.78 no 3 months ago 019bab3b-abc4-7372-ab15-5b46ebf8eb01
medium codex Initializer can be called by any address, enabling hostile initialization 0xa029a744b4e44e22f68a1bb9a848caafbf6bb233 $57,656.35 no 3 months ago 019bab3b-abbc-7163-9153-9fe872130821
medium detector ETH value transfer possible 0x524818cb8081941b618613c6f990c17bb3da0866 $0.00 no no 3 months ago 019bab3d-6eaf-71cf-a4ce-ac665330e14b
medium detector Untrusted CALL target/value reachable 0x524818cb8081941b618613c6f990c17bb3da0866 $0.00 no no 3 months ago 019bab3d-6eaf-71cf-a4ce-ac665330e14b
info cast Heavy CALL-family usage 0x524818cb8081941b618613c6f990c17bb3da0866 $0.00 no 3 months ago 019bab3d-6eaf-71cf-a4ce-ac665330e14b
info cast Heavy EXTCODE*/BALANCE usage 0x524818cb8081941b618613c6f990c17bb3da0866 $0.00 no 3 months ago 019bab3d-6eaf-71cf-a4ce-ac665330e14b
medium codex Computed CALL targets and values enable arbitrary external calls if user-controlled 0x887910314a3bfbe7b6ea0c5fbf3b9fd2fcac89d1 $57,782.76 no 3 months ago 019bab3b-abb6-709a-a874-ab08c52922a5
medium codex External call occurs before storage update on at least one path 0x887910314a3bfbe7b6ea0c5fbf3b9fd2fcac89d1 $57,782.76 no 3 months ago 019bab3b-abb6-709a-a874-ab08c52922a5
low codex Return-data handling for external calls is unclear 0x887910314a3bfbe7b6ea0c5fbf3b9fd2fcac89d1 $57,782.76 no 3 months ago 019bab3b-abb6-709a-a874-ab08c52922a5
medium slither Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): 0x48bbcfb36e5afb24dbfe7d8e50f03004c8dbe4bd $57,828.19 no 3 months ago 019bab3b-abaf-70c8-84c7-892bcfe264be
medium slither Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): 0x48bbcfb36e5afb24dbfe7d8e50f03004c8dbe4bd $57,828.19 no 3 months ago 019bab3b-abaf-70c8-84c7-892bcfe264be
medium codex Potentially unguarded arbitrary CALL with ETH value (reachability unclear) 0x367ba7d034abf0b97bccdf07fd95217410c9dbe8 $57,950.00 no 3 months ago 019bab3b-aba8-711d-8ff4-ada11975c85e
medium slither Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): 0xe472a9450974d9bae8be0eaebe556dfc892297cd $57,992.39 no 3 months ago 019bab3b-aba0-727c-a10f-8b74388affa9
medium slither Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): 0xe472a9450974d9bae8be0eaebe556dfc892297cd $57,992.39 no 3 months ago 019bab3b-aba0-727c-a10f-8b74388affa9
high slither FeeManager.claimFee(uint256) (contracts/Contract.sol#154-167) sends eth to arbitrary user 0xe87227adf0fd3f6e580e2825069a0f8e8da66ad0 $58,131.70 no 3 months ago 019bab3b-ab99-71b5-b7c5-de651f85934f
high slither DragonCurve.refund(uint256) (src/DragonCurve.sol#156-161) sends eth to arbitrary user 0x000000000000c94ed90488d3ac687a2673c2b6fb $58,170.88 no 3 months ago 019bab3b-ab92-73e3-a078-3ec5304af404
high slither DragonCurve.refundFrom(address,uint256) (src/DragonCurve.sol#162-172) sends eth to arbitrary user 0x000000000000c94ed90488d3ac687a2673c2b6fb $58,170.88 no 3 months ago 019bab3b-ab92-73e3-a078-3ec5304af404
medium slither OperatorFilterer._registerForOperatorFiltering(address,bool).functionSelector__registerForOperatorFiltering_asm_0 (lib/closedsea/src/OperatorFilterer.sol#30-31) is written in both 0x000000000000c94ed90488d3ac687a2673c2b6fb $58,170.88 no 3 months ago 019bab3b-ab92-73e3-a078-3ec5304af404
medium codex External CALLs use computed targets/value without detectable guards 0x173a5c5e0106ca4f49ce91f042e32af97974035b $58,249.46 no 3 months ago 019bab3b-ab8b-724a-92a5-927090d81b9e
low codex Initializable pattern detected; proxy initialization must be verified 0x173a5c5e0106ca4f49ce91f042e32af97974035b $58,249.46 no 3 months ago 019bab3b-ab8b-724a-92a5-927090d81b9e
high detector ETH value transfer possible 0xd9537f37fb0c7c6219b1d929688d4553d7735fdc $0.00 no no 3 months ago 019bab3d-3c25-70db-987e-c40123e1a189
high detector Untrusted CALL target/value reachable 0xd9537f37fb0c7c6219b1d929688d4553d7735fdc $0.00 no no 3 months ago 019bab3d-3c25-70db-987e-c40123e1a189
medium detector CREATE/CREATE2 reachable 0xd9537f37fb0c7c6219b1d929688d4553d7735fdc $0.00 no no 3 months ago 019bab3d-3c25-70db-987e-c40123e1a189