-
# Lines of code
https://github.com/code-423n4/2024-01-curves/blob/516aedb7b9a8d341d0d2666c23780d2bd8a9a600/contracts/Curves.sol#L211
# Vulnerability details
### Note
Any entity with access to the …
-
0x52
high
# FundRateArbitrage is vulnerable to inflation attacks
## Summary
When index is calculated, it is figured by dividing the net value of the contract (including USDC held) by the current s…
-
scammed
High
# DefaultBondStrategy::depositCallback should not deposit the entire tvl
## Summary
Vault depositors can grief both withdrawals because `depositCallback` always deposits the entire Va…
-
alexbabits
medium
# Frontrunning `rewardValidators()` for instant rewards
## Summary
The `exchangeRate` for validators is accumulated every 12 hours when the staking manager calls `rewardValidator…
-
# Lines of code
https://github.com/code-423n4/2024-03-dittoeth/blob/91faf46078bb6fe8ce9f55bcb717e5d2d302d22e/contracts/facets/RedemptionFacet.sol#L224
# Vulnerability details
## Introduction
The …
-
crypticdefense
medium
# ApproveSwapAndPay.sol swap functions lack slippage protection, leading to loss of user funds
## Summary
The `ApproveSwapAndPay::_callExternalSwap`, `ApproveSwapAndPay::_v3S…
-
> You did NOT set min price properly
Sandwich spotted in [tricrypto2](https://etherscan.io/address/0xD51a44d3FaE010294C616388b506AcdA1bfAAE46/)
[Frontrun](https://etherscan.io/tx/0xae7c5e5004fd89355…
-
# Lines of code
https://github.com/code-423n4/2024-03-revert-lend/blob/435b054f9ad2404173f36f0f74a5096c894b12b7/src/V3Vault.sol#L1138
https://github.com/code-423n4/2024-03-revert-lend/blob/435b054f9a…
-
EgisSecurity
high
# StrategyPassiveManagerVelodrome.sol - `_addLiquidity` can be DoS'ed constantly
## Summary
## Vulnerability Detail
The protocol interacts with the Velodrome `nftManager`, when i…
-
# Lines of code
https://github.com/code-423n4/2024-01-salty/blob/53516c2cdfdfacb662cdea6417c52f23c94d5b5b/src/scenario_tests/Comprehensive1.t.sol#L132-L133
https://github.com/code-423n4/2024-01-salty…