|
low
|
codex |
Fallback allows calldata-driven external CALLs with ETH value transfers |
0x3de8eb830000f1d914294d000051000031a81d00
|
$59,891.96 |
no
|
—
|
3 months ago
|
019bab3b-aa82-7335-b614-433ed19c750a
|
|
medium
|
codex |
Computed low-level CALLs may be reachable by untrusted callers |
0xf652d990e50af27d8d423ac80631b4f5ef6d4113
|
$59,926.04 |
no
|
—
|
3 months ago
|
019bab3b-aa70-7067-80e5-886b31472ece
|
|
low
|
codex |
Low-level CALLs do not validate return data |
0xf652d990e50af27d8d423ac80631b4f5ef6d4113
|
$59,926.04 |
no
|
—
|
3 months ago
|
019bab3b-aa70-7067-80e5-886b31472ece
|
|
low
|
codex |
Value-carrying CALLs use computed target/value (untrusted call risk, unconfirmed) |
0x9c5570e4615b1b1ae72f878edccb73b3951d0cb0
|
$59,990.27 |
no
|
—
|
3 months ago
|
019bab3b-aa63-72d5-84fa-0e2c93349ffe
|
|
medium
|
codex |
SELFDESTRUCT opcodes present with no detected guards |
0xd47b0f5d0a24191fdd6878fcde3f03dd4735adc1
|
$60,000.00 |
no
|
—
|
3 months ago
|
019bab3b-aa5a-71ce-8f7e-70bc3f037e9d
|
|
medium
|
codex |
Computed external CALL(s) with possible ETH value transfer and unclear target control |
0xd47b0f5d0a24191fdd6878fcde3f03dd4735adc1
|
$60,000.00 |
no
|
—
|
3 months ago
|
019bab3b-aa5a-71ce-8f7e-70bc3f037e9d
|
|
high
|
slither |
SquirrelStash.withdrawTokenInternal(address,address,uint256) (contracts/Contract.sol#236-245) ignores return value by ERC20(token).transfer(recipient,amount) (contracts/Contract... |
0x3d88fc5d3fb84caf45011a790a994928789c31a8
|
$60,000.97 |
no
|
—
|
3 months ago
|
019bab3b-aa50-70a2-8a41-e573c49b0a5e
|
|
high
|
slither |
SquirrelStash.withdrawEthInternal(address,uint256) (contracts/Contract.sol#252-261) sends eth to arbitrary user |
0x3d88fc5d3fb84caf45011a790a994928789c31a8
|
$60,000.97 |
no
|
—
|
3 months ago
|
019bab3b-aa50-70a2-8a41-e573c49b0a5e
|
|
medium
|
codex |
Admin removal corrupts index mapping, making some admins non-removable |
0x3d88fc5d3fb84caf45011a790a994928789c31a8
|
$60,000.97 |
no
|
—
|
3 months ago
|
019bab3b-aa50-70a2-8a41-e573c49b0a5e
|
|
low
|
codex |
Whitelist removal corrupts index mapping, making some recipients non-removable |
0x3d88fc5d3fb84caf45011a790a994928789c31a8
|
$60,000.97 |
no
|
—
|
3 months ago
|
019bab3b-aa50-70a2-8a41-e573c49b0a5e
|
|
low
|
codex |
Unchecked ERC20 transfer return in token withdrawals |
0x3d88fc5d3fb84caf45011a790a994928789c31a8
|
$60,000.97 |
no
|
—
|
3 months ago
|
019bab3b-aa50-70a2-8a41-e573c49b0a5e
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): |
0x3b7b9616f30a52cdedb973515e415e3d96b301f5
|
$60,014.66 |
no
|
—
|
3 months ago
|
019bab3b-aa49-729f-bf4f-0be2b2c2bab9
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): |
0x3b7b9616f30a52cdedb973515e415e3d96b301f5
|
$60,014.66 |
no
|
—
|
3 months ago
|
019bab3b-aa49-729f-bf4f-0be2b2c2bab9
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): |
0x290a6a7460b308ee3f19023d2d00de604bcf5b42
|
$60,082.34 |
no
|
—
|
3 months ago
|
019bab3b-aa42-706d-b8a4-96d6c0b83ee2
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): |
0x290a6a7460b308ee3f19023d2d00de604bcf5b42
|
$60,082.34 |
no
|
—
|
3 months ago
|
019bab3b-aa42-706d-b8a4-96d6c0b83ee2
|
|
critical
|
codex |
Hardcoded tx.origin bypass disables SNARK verification |
0x9a3152b61420ed4d5e594c0b48bb932ee41b7376
|
$60,124.91 |
no
|
—
|
3 months ago
|
019bab3b-aa3a-72d1-b401-bae32ceffc05
|
|
high
|
detector |
Untrusted DELEGATECALL target reachable |
0xb157dc78c2815280906a6730984a5e0dca65e247
|
$0.00 |
no
|
no
|
3 months ago
|
019bab3c-03ac-7154-aa8e-81b80b4bfd3c
|
|
high
|
detector |
Authorization based on tx.origin |
0xb157dc78c2815280906a6730984a5e0dca65e247
|
$0.00 |
no
|
—
|
3 months ago
|
019bab3c-03ac-7154-aa8e-81b80b4bfd3c
|
|
medium
|
detector |
ETH value transfer possible |
0xb157dc78c2815280906a6730984a5e0dca65e247
|
$0.00 |
no
|
no
|
3 months ago
|
019bab3c-03ac-7154-aa8e-81b80b4bfd3c
|
|
medium
|
detector |
Untrusted CALL target/value reachable |
0xb157dc78c2815280906a6730984a5e0dca65e247
|
$0.00 |
no
|
no
|
3 months ago
|
019bab3c-03ac-7154-aa8e-81b80b4bfd3c
|
|
medium
|
cast |
DELEGATECALL present |
0xb157dc78c2815280906a6730984a5e0dca65e247
|
$0.00 |
no
|
—
|
3 months ago
|
019bab3c-03ac-7154-aa8e-81b80b4bfd3c
|
|
info
|
cast |
Heavy CALL-family usage |
0xb157dc78c2815280906a6730984a5e0dca65e247
|
$0.00 |
no
|
—
|
3 months ago
|
019bab3c-03ac-7154-aa8e-81b80b4bfd3c
|
|
high
|
detector |
ETH value transfer possible |
0x8d1fa828e0b99f2cd9bec6c51ff11e97b502db8a
|
$0.00 |
no
|
no
|
3 months ago
|
019bab3b-fcd0-7290-bd8b-dd7b4bf015df
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x8d1fa828e0b99f2cd9bec6c51ff11e97b502db8a
|
$0.00 |
no
|
no
|
3 months ago
|
019bab3b-fcd0-7290-bd8b-dd7b4bf015df
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): |
0xdbff8e02dbf57e66168f3d22ae819567b1e39d47
|
$60,214.20 |
no
|
—
|
3 months ago
|
019bab3b-aa29-7091-8c4f-2decea98acaa
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): |
0xdbff8e02dbf57e66168f3d22ae819567b1e39d47
|
$60,214.20 |
no
|
—
|
3 months ago
|
019bab3b-aa29-7091-8c4f-2decea98acaa
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): |
0x94981f69f7483af3ae218cbfe65233cc3c60d93a
|
$60,259.42 |
no
|
—
|
3 months ago
|
019bab3b-aa21-7213-aae5-c92013f48705
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): |
0x94981f69f7483af3ae218cbfe65233cc3c60d93a
|
$60,259.42 |
no
|
—
|
3 months ago
|
019bab3b-aa21-7213-aae5-c92013f48705
|
|
high
|
slither |
StablesPool.safeBsdTransfer(address,uint256) (contracts/Contract.sol#676-685) ignores return value by bsd.transfer(_to,_amount) (contracts/Contract.sol#683-684) |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
high
|
slither |
StablesPool.safeBsdTransfer(address,uint256) (contracts/Contract.sol#676-685) ignores return value by bsd.transfer(_to,_bsdBal) (contracts/Contract.sol#682-683) |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
medium
|
slither |
Reentrancy in StablesPool.deposit(uint256,uint256) (contracts/Contract.sol#626-645): |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
medium
|
slither |
Reentrancy in StablesPool.withdraw(uint256,uint256) (contracts/Contract.sol#645-665): |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
medium
|
slither |
Reentrancy in StablesPool.emergencyWithdraw(uint256) (contracts/Contract.sol#666-674): |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
medium
|
slither |
Reentrancy in StablesPool.withdraw(uint256,uint256) (contracts/Contract.sol#645-665): |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
medium
|
codex |
Emergency withdrawal transfers before zeroing balances |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
medium
|
codex |
Reward payout before state update enables reentrancy double-claims |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
low
|
codex |
Unchecked ERC20 return values on reward transfers |
0xa249ee8255df0aa00a15262b16bca3efd66c3e4c
|
$60,260.56 |
no
|
—
|
3 months ago
|
019bab3b-aa19-71a6-879c-a96e48ff592a
|
|
high
|
slither |
BoringVault.enter(address,ERC20,uint256,address,uint256) (src/base/BoringVault.sol#74-85) uses arbitrary from in transferFrom: asset.safeTransferFrom(from,address(this),assetAmo... |
0x83599937c2c9bea0e0e8ac096c6f32e86486b410
|
$60,443.62 |
no
|
—
|
3 months ago
|
019bab3b-aa09-7136-8249-3b5f5266a02c
|
|
high
|
detector |
Authorization based on tx.origin |
0xc3fe3e0ea967b2878fab2fec7e1067b32adf1c03
|
$0.00 |
no
|
—
|
3 months ago
|
019bab3b-cd42-72ee-8d44-36346e11fccc
|
|
medium
|
detector |
Untrusted CALL target/value reachable |
0xc3fe3e0ea967b2878fab2fec7e1067b32adf1c03
|
$0.00 |
no
|
no
|
3 months ago
|
019bab3b-cd42-72ee-8d44-36346e11fccc
|
|
medium
|
detector |
ETH value transfer possible |
0xc3fe3e0ea967b2878fab2fec7e1067b32adf1c03
|
$0.00 |
no
|
no
|
3 months ago
|
019bab3b-cd42-72ee-8d44-36346e11fccc
|
|
medium
|
codex |
Hardcoded DELEGATECALL grants external target full control over this contract’s storage |
0xccefbf06e69039df9632ea8b5484a8890d46bbbc
|
$60,558.93 |
no
|
—
|
3 months ago
|
019bab3b-a9f9-7335-a4c5-15d93b6096dc
|
|
medium
|
codex |
External CALL before state update (potential reentrancy) |
0xf564141bda167a0f2c87ffd4480be627d90fa954
|
$60,813.08 |
no
|
—
|
3 months ago
|
019bab3b-a9f0-7106-bd41-4d2ed4375abc
|
|
low
|
codex |
External CALL targets/values are computed (audit address control) |
0xf564141bda167a0f2c87ffd4480be627d90fa954
|
$60,813.08 |
no
|
—
|
3 months ago
|
019bab3b-a9f0-7106-bd41-4d2ed4375abc
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): |
0xc789130a5b127449f439d17267744d24d69a5876
|
$60,962.98 |
no
|
—
|
3 months ago
|
019bab3b-a9e8-72a6-a992-0fbbcfd46e2f
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): |
0xc789130a5b127449f439d17267744d24d69a5876
|
$60,962.98 |
no
|
—
|
3 months ago
|
019bab3b-a9e8-72a6-a992-0fbbcfd46e2f
|
|
high
|
slither |
GovTreasurer.safeGDAOTransfer(address,uint256) (contracts/Contract.sol#1105-1113) ignores return value by gdao.transfer(_to,GDAOBal) (contracts/Contract.sol#1109-1110) |
0x4dac3e07316d2a31baabb252d89663dee8f76f09
|
$61,154.96 |
no
|
—
|
3 months ago
|
019bab3b-a9ce-7222-9441-b6180eb0d007
|
|
high
|
slither |
GovTreasurer.safeGDAOTransfer(address,uint256) (contracts/Contract.sol#1105-1113) ignores return value by gdao.transfer(_to,_amount) (contracts/Contract.sol#1112-1113) |
0x4dac3e07316d2a31baabb252d89663dee8f76f09
|
$61,154.96 |
no
|
—
|
3 months ago
|
019bab3b-a9ce-7222-9441-b6180eb0d007
|
|
medium
|
slither |
Reentrancy in GovTreasurer.withdraw(uint256,uint256) (contracts/Contract.sol#1089-1104): |
0x4dac3e07316d2a31baabb252d89663dee8f76f09
|
$61,154.96 |
no
|
—
|
3 months ago
|
019bab3b-a9ce-7222-9441-b6180eb0d007
|
|
medium
|
slither |
Reentrancy in GovTreasurer.updatePool(uint256) (contracts/Contract.sol#1030-1040): |
0x4dac3e07316d2a31baabb252d89663dee8f76f09
|
$61,154.96 |
no
|
—
|
3 months ago
|
019bab3b-a9ce-7222-9441-b6180eb0d007
|