issues
search
code-423n4
/
2023-09-asymmetry-findings
2
stars
1
forks
source link
issues
Newest
Newest
Most commented
Recently updated
Oldest
Least commented
Least recently updated
Lack of slippage protection for `depositRewards()` in `AfEth.sol` makes it susceptible to sandwich attacks
#24
c4-submissions
closed
9 months ago
19
Functions in the `VotiumStrategy` contract are susceptible to sandwich attacks
#23
c4-submissions
opened
9 months ago
12
QA Report
#22
c4-submissions
opened
9 months ago
1
Gas Optimizations
#21
c4-submissions
opened
9 months ago
2
`VotiumStrategy.requestWithdraw()` doesn't check whether `totalLockedBalancePlusUnlockable` is already enough to cover withdrawal being requested
#20
c4-submissions
closed
9 months ago
2
The current vlCVX balance is not freezed, when withdrawal has been requested
#19
c4-submissions
closed
9 months ago
3
WithdrawTime is incorrectly determined during withdrawal request being submitted
#18
c4-submissions
closed
9 months ago
41
Oracle data feeds are insufficiently validated
#17
c4-submissions
closed
9 months ago
8
It might not be possible to `applyRewards()`, if an amount received is less than 0.05 eth
#16
c4-submissions
opened
9 months ago
7
Potential rewards stealing by manipulating CVX/ETH pool
#15
c4-submissions
closed
9 months ago
11
Attacker can mint afEth tokens with different ratio
#14
c4-submissions
opened
9 months ago
21
AfEth withdrawing will not work when ratio will be 0
#13
c4-submissions
closed
9 months ago
16
AfEth.depositRewards should revert when pauseDeposit
#12
c4-submissions
opened
9 months ago
10
Stale cvx price can be used while depositing
#11
c4-submissions
closed
9 months ago
11
AfEth.withdrawTime function works incorrectly
#10
c4-submissions
opened
9 months ago
14
VotiumStrategyCore.applyRewards can be sandwhiched to make profit
#9
c4-submissions
closed
9 months ago
6
VotiumStrategyCore.applyRewards can be sandwhiched
#8
c4-submissions
closed
9 months ago
4
Attacker can mint afEth with cheaper price
#7
c4-submissions
closed
9 months ago
4
Gas Optimizations
#6
c4-submissions
opened
9 months ago
1
QA Report
#5
c4-submissions
opened
9 months ago
4
Last stakers may not receive funds back
#4
c4-submissions
closed
9 months ago
2
VotiumStrategy.withdrawTime doesn't expect that balance can be already unlocked
#3
c4-submissions
closed
9 months ago
3
AfEth.requestWithdraw function calculates withdraw time incorrectly
#2
c4-submissions
opened
9 months ago
9
Agreements & Disclosures
#1
code423n4
opened
10 months ago
0
Previous