-
**Github username:** --
**Twitter username:** --
**Submission hash (on-chain):** 0xaf1a5eeff9e700e9c7fa7560a4353a8fb8e3c8c3a647e31952527588ed7be2ba
**Severity:** high
**Description:**
# Transfer Has…
-
**Github username:** --
**Twitter username:** --
**Submission hash (on-chain):** 0x1c59c2346e8d70837bd9c3a0ae00359496f372f23e0c779095011d6aabff5766
**Severity:** medium
**Description:**
**Descriptio…
-
**Github username:** --
**Twitter username:** --
**Submission hash (on-chain):** 0x6666ae18566f89839a3fe0021ded453fc0b6b4a7daaaf6da7f7c060d4865273f
**Severity:** high
**Description:**
**Description*…
-
g
High
# Transfers from the rebate manager's token vault always fail due to lack of bump seed
### Summary
The bump seed is not included in the signer seed for the transfer transaction which will c…
-
**Github username:** @0xmahdirostami
**Twitter username:** 0xmahdirostami
**Submission hash (on-chain):** 0x6be64ca3e8c2415e14b45b3c12e1a5d29be34ad727a750220815f2af71ea84ae
**Severity:** high
**Desc…
-
In transfer workflow, very first step involved Old Arch giving that secret shard data to a New Archaeologist.
What if the New Archaeologist is just trying to screw over the Old Archaeologist? They …
-
**Github username:** @00xWizard
**Twitter username:** 00xWizard
**Submission hash (on-chain):** 0x30a87d83a9b0254a721d7d3b5f7f511ca2d364a142ea8d92dbfbf18e88f8b948
**Severity:** low
**Description:**
…
-
xKeywordx
High
# [H-1] - User can deposit unauthorized tokens, leading to incorrect crediting of USDC on the other chain.
### Summary
There are no checks to ensure that the `deposit_token` match…
-
- [ ] Is there existing cheatsheets at [OWASP Cheatsheets](https://cheatsheetseries.owasp.org/Glossary.html)
- [ ] If there is an existing cheatsheet, does it need updating at the source to cater for …
-
vatsal
High
# rounding error due to internal accounting and can steal some portion of the first depositors funds
## Summary
## Vulnerability Detail
- where: All basepool
- when: Total Supply of…