-
Ironsidesec
medium
# Sandwich attack on `OCL_ZVE.forwardYield`
## Summary
This issue is due to the wrong slippage implementation. Cannot be fixed by access control. Still, it can be sandwiched by M…
-
Ironsidesec
medium
# No slippage for ZVE rewards when depositing to tranches.
## Summary
Whenever there is an exchange of value or reward transfer, there should be a minimum slippage input paramete…
-
dimulski
high
# Revoking user vesting DOSes the last withdrawers
## Summary
In the ``ZivoeRewardsVesting.sol`` contract a vesting schedule can be created either by the ``ZivoeITO.sol`` contract, ba…
-
### Steps
Incorrectly flags wallets as a drainer as long as its 2 txs in the same block by that wallet, even if its only 2 buys like this one, no sells
![image](https://github.com/dextools-io/commun…
-
# Lines of code
https://github.com/code-423n4/2024-05-loop/blob/main/src/PrelaunchPoints.sol#L321
# Vulnerability details
## Impact
An attacker can break the ETH/lpETH 1:1 conversion by frontrunn…
-
st0yanov
medium
# Prefunded deposits to children of `BaseLSTAdapter` could be lost and shares stolen
## Summary
Transfers of underlying token (WETH) to `BaseLSTAdapter`'s child contracts (`StEtherA…
-
# Lines of code
https://github.com/code-423n4/2024-02-ai-arena/blob/cd1a0e6d1b40168657d1aaee8223dc050e15f8cc/src/RankedBattle.sol#L322-L349
https://github.com/code-423n4/2024-02-ai-arena/blob/cd1a0e6…
-
# Lines of code
https://github.com/code-423n4/2024-02-ai-arena/blob/cd1a0e6d1b40168657d1aaee8223dc050e15f8cc/src/StakeAtRisk.sol#L93-L107
https://github.com/code-423n4/2024-02-ai-arena/blob/cd1a0e6d1…
-
# Lines of code
https://github.com/code-423n4/2024-02-ai-arena/blob/main/src/RankedBattle.sol#L322-L349
# Vulnerability details
## Impact
In case of a loss, a user can prevent his **NRN** tokens …
-
# Lines of code
https://github.com/code-423n4/2024-01-salty/blob/53516c2cdfdfacb662cdea6417c52f23c94d5b5b/src/staking/Liquidity.sol#L107
https://github.com/code-423n4/2024-01-salty/blob/53516c2cdfdfa…