-
**Github username:** @Audinarey
**Twitter username:** audinarey
**Submission hash (on-chain):** 0xb7842b2d829d45a964a00bf2dd406b62602d8ceb81b01cc9e32a45347e253596
**Severity:** high
**Description:**…
-
## Title: Do not use a custom library for merkle proofs
## Impact
It is better to use widely used public libraries than custom. Source of MerkleLib.sol library is not known however functionality matc…
-
# Lines of code
https://github.com/Tapioca-DAO/tapiocaz-audit/blob/bcf61f79464cfdc0484aa272f9f6e28d5de36a8f/contracts/tOFT/modules/BaseTOFTLeverageModule.sol#L212
https://github.com/Tapioca-DAO/tapio…
-
# QA Report
## Table of Contents
- [summary](#summary)
- [Comment Missing function parameter](#comment-missing-function-parameter)
- [Commented Code](#commented-code)
- [Constants instead of magic n…
-
# Lines of code
https://github.com/Tapioca-DAO/tapioca-bar-audit/blob/2286f80f928f41c8bc189d0657d74ba83286c668/contracts/usd0/modules/USDOLeverageModule.sol#L180-L185
https://github.com/Tapioca-DAO/t…
-
# Lines of code
https://github.com/code-423n4/2022-07-golom/blob/main/contracts/core/GolomTrader.sol#L154
# Vulnerability details
### Impact
[L154](https://github.com/code-423n4/2022-07-golom/blo…
-
# Lines of code
https://github.com/Tapioca-DAO/tapiocaz-audit/blob/bcf61f79464cfdc0484aa272f9f6e28d5de36a8f/contracts/Balancer.sol#L204
https://github.com/Tapioca-DAO/tapiocaz-audit/blob/bcf61f79464c…
-
Jeiwan
high
# Cross-chain message authentication can be bypassed, allowing an attacker to disrupt the state of vaults
## Summary
A malicious actor may send a cross-chain message to an `XProv…
-
# Lines of code
https://github.com/code-423n4/2023-09-ondo/blob/main/contracts/bridge/SourceBridge.sol#L121-L129
https://github.com/code-423n4/2023-09-ondo/blob/main/contracts/bridge/DestinationBridg…
-
# remove or delete?[^1]
https://github.com/manifoldfinance/mevETH2/blob/216fe89b4b259aa768c698247b6facac9d08597e/src/libraries/Auth.sol#L52
When the difference between remove and delete is not…