|
critical
|
codex |
Anyone can become executor and gain onlyAuth privileges (ITGToken) |
0xb104df39250112eda59b27f5db7013c7ee132d50
|
$62,000.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdf4-70c0-8613-6ae209cfb88c
|
|
medium
|
codex |
Division by zero and mispricing in 2nd/4th crowdsale pricing |
0xb104df39250112eda59b27f5db7013c7ee132d50
|
$62,000.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdf4-70c0-8613-6ae209cfb88c
|
|
medium
|
codex |
Auxiliary contracts can be seized because owner is unset and setOwner is publicly callable |
0xb104df39250112eda59b27f5db7013c7ee132d50
|
$62,000.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdf4-70c0-8613-6ae209cfb88c
|
|
medium
|
codex |
Token lock bypass via transferFrom ignores locked holder |
0xb104df39250112eda59b27f5db7013c7ee132d50
|
$62,000.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdf4-70c0-8613-6ae209cfb88c
|
|
medium
|
codex |
Potentially unguarded arbitrary CALL/ETH transfer entrypoints |
0x80aa81029df9afdc70a621c86d7a81d7e9ed7e3a
|
$62,000.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdee-706f-88ec-43e0a30fb978
|
|
low
|
codex |
External CALLs can reach state writes without a detected reentrancy guard |
0x80aa81029df9afdc70a621c86d7a81d7e9ed7e3a
|
$62,000.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdee-706f-88ec-43e0a30fb978
|
|
medium
|
codex |
Allowlisted executor can perform arbitrary external CALLs with ETH value |
0xadd45159f83dada41bdd4b5c87fedafcccbdfbc6
|
$62,035.49 |
no
|
—
|
3 months ago
|
019ba9e0-bde8-721d-81bf-cec45f1439c0
|
|
low
|
codex |
External CALL to storage-derived target (possible untrusted call / reentrancy surface) |
0x123e33e6f65fe44314f863a24c58fdc2f5264f33
|
$62,041.68 |
no
|
—
|
3 months ago
|
019ba9e0-bde2-7288-8ffe-0e2a23d3c7d7
|
|
low
|
codex |
ERC20 transfer/transferFrom return values appear unchecked |
0x123e33e6f65fe44314f863a24c58fdc2f5264f33
|
$62,041.68 |
no
|
—
|
3 months ago
|
019ba9e0-bde2-7288-8ffe-0e2a23d3c7d7
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.swap(address,bool,int256,uint160,bytes) (contracts/UniswapV3Pool.sol#596-788): |
0x21e88f4482cd48deab1ca5eddabdfb14cb8ad76f
|
$62,149.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdda-7121-8cc1-a843384bc853
|
|
medium
|
slither |
Reentrancy in UniswapV3Pool.collectProtocol(address,uint128,uint128) (contracts/UniswapV3Pool.sol#848-868): |
0x21e88f4482cd48deab1ca5eddabdfb14cb8ad76f
|
$62,149.00 |
no
|
—
|
3 months ago
|
019ba9e0-bdda-7121-8cc1-a843384bc853
|
|
medium
|
codex |
Mining mints based on requested amount instead of actual tokens received |
0x30c92c69d38cfacbb28081490f8cd7558d441903
|
$62,184.55 |
no
|
—
|
3 months ago
|
019ba9e0-bdd3-73a4-834d-be6cc25079ff
|
|
low
|
codex |
Unchecked ERC20 transfer return values can silently fail in swaps and refunds |
0x30c92c69d38cfacbb28081490f8cd7558d441903
|
$62,184.55 |
no
|
—
|
3 months ago
|
019ba9e0-bdd3-73a4-834d-be6cc25079ff
|
|
medium
|
codex |
Dividend claims can revert due to division by zero |
0x57b116da40f21f91aec57329ecb763d29c1b2355
|
$62,196.03 |
no
|
—
|
3 months ago
|
019ba9e0-bdc9-72e5-aa7a-9085659cd028
|
|
medium
|
codex |
Raffle winner selection is miner/owner-influenced |
0x57b116da40f21f91aec57329ecb763d29c1b2355
|
$62,196.03 |
no
|
—
|
3 months ago
|
019ba9e0-bdc9-72e5-aa7a-9085659cd028
|
|
low
|
codex |
Attack flow breaks goo supply accounting |
0x57b116da40f21f91aec57329ecb763d29c1b2355
|
$62,196.03 |
no
|
—
|
3 months ago
|
019ba9e0-bdc9-72e5-aa7a-9085659cd028
|
|
medium
|
codex |
GoFastCaller leaves approvals in place, allowing previous recipients to drain future tokens |
0x5afdab84d684a057d359498e40f38f433390e711
|
$0.00 |
no
|
—
|
3 months ago
|
019ba9bd-975f-73b1-8c6a-5aab9a2fbec6
|
|
low
|
codex |
Permit-based order submission uses a global nonce that can be cheaply griefed |
0x5afdab84d684a057d359498e40f38f433390e711
|
$0.00 |
no
|
—
|
3 months ago
|
019ba9bd-975f-73b1-8c6a-5aab9a2fbec6
|
|
medium
|
codex |
tx.origin-based authorization/guard detected |
0xa6f27fa3c60ec70d5ac7ea53cad339498bc1580e
|
$0.00 |
no
|
—
|
3 months ago
|
019ba9bd-8206-7335-b79d-7b327b7d19bd
|
|
low
|
codex |
External CALL with value; target/return handling unclear |
0xa6f27fa3c60ec70d5ac7ea53cad339498bc1580e
|
$0.00 |
no
|
—
|
3 months ago
|
019ba9bd-8206-7335-b79d-7b327b7d19bd
|
|
high
|
slither |
OriginalTokenBridgeUpgradable._nonblockingLzReceive(uint16,bytes,uint64,bytes) (contracts/Contract.sol#2920-2940) sends eth to arbitrary user |
0x12f7fc7154ed511e3df48c8092ad130a7a36701b
|
$0.00 |
no
|
—
|
3 months ago
|
019ba9bd-755b-7061-a621-ecfd739dc3eb
|
|
low
|
codex |
Owner-only function can execute arbitrary external CALLs (computed target/value) |
0xe97f36717a51fd61c54f35e8fb2ca49d82c121bd
|
$0.00 |
no
|
—
|
3 months ago
|
019ba9bd-678e-713e-83c6-d1ece50b7ce0
|
|
medium
|
codex |
Dex vault rebalance can skip native allowance decrement based on protocol-supplied return values |
0xfb3102759f2d57f547b9c519db49ce1ffde15db2
|
$0.00 |
no
|
—
|
3 months ago
|
019ba9bd-3bd2-7165-b27e-350fe4b4d11c
|
|
medium
|
detector |
ETH value transfer possible |
0xd0eabb5164c9dba0a2ee508f7e8d91d4d485637c
|
$61,158.01 |
no
|
no
|
3 months ago
|
019ba9e0-be62-7229-9471-8381484dc66b
|
|
medium
|
detector |
Untrusted CALL target/value reachable |
0xd0eabb5164c9dba0a2ee508f7e8d91d4d485637c
|
$61,158.01 |
no
|
no
|
3 months ago
|
019ba9e0-be62-7229-9471-8381484dc66b
|
|
info
|
cast |
Heavy EXTCODE*/BALANCE usage |
0xd0eabb5164c9dba0a2ee508f7e8d91d4d485637c
|
$61,158.01 |
no
|
—
|
3 months ago
|
019ba9e0-be62-7229-9471-8381484dc66b
|
|
medium
|
detector |
ETH value transfer possible |
0x1bc841d3080bd4f4c64bd207206ebd3774bb108a
|
$61,161.45 |
no
|
no
|
3 months ago
|
019ba9e0-be5b-71bb-91d9-6a8a62afc404
|
|
medium
|
detector |
Untrusted CALL target/value reachable |
0x1bc841d3080bd4f4c64bd207206ebd3774bb108a
|
$61,161.45 |
no
|
no
|
3 months ago
|
019ba9e0-be5b-71bb-91d9-6a8a62afc404
|
|
high
|
detector |
Authorization based on tx.origin |
0xb4db55a20e0624edd82a0cf356e3488b4669bd27
|
$61,189.35 |
no
|
—
|
3 months ago
|
019ba9e0-be54-719a-98cc-7586b241db49
|
|
medium
|
detector |
Untrusted CALL target/value reachable |
0xb4db55a20e0624edd82a0cf356e3488b4669bd27
|
$61,189.35 |
no
|
no
|
3 months ago
|
019ba9e0-be54-719a-98cc-7586b241db49
|
|
medium
|
detector |
CREATE/CREATE2 reachable |
0xb4db55a20e0624edd82a0cf356e3488b4669bd27
|
$61,189.35 |
no
|
no
|
3 months ago
|
019ba9e0-be54-719a-98cc-7586b241db49
|
|
medium
|
detector |
ETH value transfer possible |
0xb4db55a20e0624edd82a0cf356e3488b4669bd27
|
$61,189.35 |
no
|
no
|
3 months ago
|
019ba9e0-be54-719a-98cc-7586b241db49
|
|
low
|
cast |
Contract creation opcode present |
0xb4db55a20e0624edd82a0cf356e3488b4669bd27
|
$61,189.35 |
no
|
—
|
3 months ago
|
019ba9e0-be54-719a-98cc-7586b241db49
|
|
info
|
cast |
Heavy CALL-family usage |
0xb4db55a20e0624edd82a0cf356e3488b4669bd27
|
$61,189.35 |
no
|
—
|
3 months ago
|
019ba9e0-be54-719a-98cc-7586b241db49
|
|
info
|
cast |
Heavy EXTCODE*/BALANCE usage |
0xb4db55a20e0624edd82a0cf356e3488b4669bd27
|
$61,189.35 |
no
|
—
|
3 months ago
|
019ba9e0-be54-719a-98cc-7586b241db49
|
|
high
|
detector |
ETH value transfer possible |
0xd3541ad19c9523c268ede8792310867c57be39e4
|
$61,213.11 |
no
|
no
|
3 months ago
|
019ba9e0-be4e-714d-aed0-7ba11a65552c
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0xd3541ad19c9523c268ede8792310867c57be39e4
|
$61,213.11 |
no
|
no
|
3 months ago
|
019ba9e0-be4e-714d-aed0-7ba11a65552c
|
|
info
|
cast |
Heavy EXTCODE*/BALANCE usage |
0xd3541ad19c9523c268ede8792310867c57be39e4
|
$61,213.11 |
no
|
—
|
3 months ago
|
019ba9e0-be4e-714d-aed0-7ba11a65552c
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x0d45c292bacdc47ce850e4c83a2fa2e8509ded5d
|
$61,333.21 |
no
|
no
|
3 months ago
|
019ba9e0-be48-720c-a102-08146df132cf
|
|
high
|
detector |
ETH value transfer possible |
0x0d45c292bacdc47ce850e4c83a2fa2e8509ded5d
|
$61,333.21 |
no
|
no
|
3 months ago
|
019ba9e0-be48-720c-a102-08146df132cf
|
|
high
|
detector |
Authorization based on tx.origin |
0x69af81e73a73b40adf4f3d4223cd9b1ece623074
|
$61,396.66 |
no
|
—
|
3 months ago
|
019ba9e0-be43-721d-9b34-673f32360136
|
|
high
|
detector |
ETH value transfer possible |
0x14424eeecbff345b38187d0b8b749e56faa68539
|
$61,397.20 |
no
|
no
|
3 months ago
|
019ba9e0-be3e-71ec-a39f-602b09db9395
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x14424eeecbff345b38187d0b8b749e56faa68539
|
$61,397.20 |
no
|
no
|
3 months ago
|
019ba9e0-be3e-71ec-a39f-602b09db9395
|
|
info
|
cast |
Heavy EXTCODE*/BALANCE usage |
0x14424eeecbff345b38187d0b8b749e56faa68539
|
$61,397.20 |
no
|
—
|
3 months ago
|
019ba9e0-be3e-71ec-a39f-602b09db9395
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x700f4dc28170f9903faa6da32d6663ff1ac94f27
|
$61,437.63 |
no
|
no
|
3 months ago
|
019ba9e0-be38-7311-8ecb-c09707ba5585
|
|
high
|
detector |
ETH value transfer possible |
0x700f4dc28170f9903faa6da32d6663ff1ac94f27
|
$61,437.63 |
no
|
no
|
3 months ago
|
019ba9e0-be38-7311-8ecb-c09707ba5585
|
|
info
|
cast |
Heavy EXTCODE*/BALANCE usage |
0x700f4dc28170f9903faa6da32d6663ff1ac94f27
|
$61,437.63 |
no
|
—
|
3 months ago
|
019ba9e0-be38-7311-8ecb-c09707ba5585
|
|
high
|
detector |
ETH value transfer possible |
0x67cb903ca9d07107784bc9398a75a0543524c353
|
$61,500.00 |
no
|
no
|
3 months ago
|
019ba9e0-be33-70d3-85ba-7d14b6e68e64
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x67cb903ca9d07107784bc9398a75a0543524c353
|
$61,500.00 |
no
|
no
|
3 months ago
|
019ba9e0-be33-70d3-85ba-7d14b6e68e64
|
|
high
|
detector |
Untrusted CALL target/value reachable |
0x517f451b0a9e1b87dc0ae98a05ee033c3310f046
|
$61,768.18 |
no
|
no
|
3 months ago
|
019ba9e0-be2c-7328-9110-556dabb406d4
|