-
**Github username:** @0xRizwan
**Twitter username:** 0xRizwann
**Submission hash (on-chain):** 0x9fc9deb56a92f2424bc44de75850d1599eb64cf924da445f14082b576b757278
**Severity:** medium
**Description:*…
-
# Handle
thank_you
# Vulnerability details
## Impact
UniswapHandler utilizes UniswapV2Router to swap, add liquidity, and remove liquidity with the UniswapV2Pair contract. In order to utilize these…
-
# Lines of code
https://github.com/Tapioca-DAO/tap-token-audit/blob/59749be5bc2286f0bdbf59d7ddc258ddafd49a9f/contracts/options/oTAP.sol?plain=1#L126
https://github.com/Tapioca-DAO/tap-token-audit/blo…
-
keccak123
high
# User specified slippage allows frontrunning
## Summary
`rebalance` and `rebalanceLite` can be called by any user. Assets are taken from a user specified `account` address which ha…
-
The function `TroveManager._openTrove` computes the trove ID from the owner address and a trove index chosen by the caller. Anyone can open a trove on behalf of another `_owner` by providing the neces…
-
# Lines of code
https://github.com/code-423n4/2023-04-frankencoin/blob/main/contracts/Equity.sol#L309-L316
# Vulnerability details
## Impact
The Bank protocol is designed in such a way, if it is n…
-
PUSH0
medium
# Frontrunning validator freeze to withdraw tokens
## Summary
Covalent implements a freeze mechanism to disable malicious Validators, this allows the protocol to block all interaction…
-
### Description
`Codeup::claimCodeupERC20()` does not set minimum values for adding liquidity or swapping (sets 0) and places a deadline of `block.timestamp`, which means mev bots may sandwich thes…
-
## Description
Addition of Blockchain / Crypto Related Vulnerabilities from protocols, smart contracts, and zero knowledge.
## Changes
**Decentralized Application Misconfiguration**
Decentra…
nnons updated
5 hours ago
-
# Handle
tensors
# Vulnerability details
## Impact
Some of the actions in TradingAction.sol can be frontrun. Since there are no slippage protections, its unclear how bad this problem can be.
## P…