TW
Tripwire
Find contracts. Test them. Review real vulns.
Contract
0xc1c5b18774d0282949331b719b5ea4a21cbc62c8 checked chain 1
Dedaub
Queue = batch runner. Audit = immediate run. Audit + LLM forces codex.
Value & Balances
$0.00
last balance 3 months ago
ETH
0.0000
WETH
0.0000
USDC
0.00
USDT
0.00
Findings Signal
0
confirmed findings
crit 0 high 0 unconfirmed 13 total 13
validated = confirmed for call sinks; sink observed for others

Proxy & Workflow

linkage
Proxy status
non-proxy
Implementation address
Proxies pointing here
1
View top proxies
Workflow
checked
attempts 0
checked 3 months ago

Latest Findings

validated = confirmed for call sinks; sink observed for others
No confirmed findings yet.
Show unconfirmed findings
Severity Tool Title Validated Confirmed
high slither VaultLib.processor(address[],uint256[],bytes[]) (src/library/VaultLib.sol#319-336) sends eth to arbitrary user no
high slither TimelockController._execute(address,uint256,bytes) (lib/openzeppelin-contracts/contracts/governance/TimelockController.sol#412-415) sends eth to arbitrary user no
high detector Untrusted DELEGATECALL target reachable no no
high codex processAccounting ignores buffer/strategy assets, enabling share price manipulation no
high detector Authorization based on tx.origin no
medium detector Untrusted CALL target/value reachable no no
medium detector CREATE/CREATE2 reachable no no
medium cast DELEGATECALL present no
medium detector ETH value transfer possible no no
medium codex Share pricing fully trusts provider rates without validation or staleness checks no
low codex Fee-on-transfer tokens can inflate shares and totalAssets no
low cast Contract creation opcode present no
info cast Heavy EXTCODE*/BALANCE usage no

Codex

latest run
complete source findings
Found 3 issues: accounting ignores buffer-held assets (share price manipulation), unguarded oracle rates, and fee-on-transfer deposits can inflate shares.
Top findings
  • high processAccounting ignores buffer/strategy assets, enabling share price manipulation
  • medium Share pricing fully trusts provider rates without validation or staleness checks
  • low Fee-on-transfer tokens can inflate shares and totalAssets

Code Metadata

fingerprint
Created block
Code size
19303
Codehash
0x6472eb6ace72e4a0c84a9035d74b066e17567252e18d27d3bd2374b8948ac6db
Priority score
0.000000
Latest run id

Recent Runs

last 20
Run ID Status Validated Total findings Created
019bab3d-c746-7355-af08-a01c5cba9495 complete crit 0 high 0 13 3 months ago