issues
search
code-423n4
/
2024-05-canto-findings
0
stars
0
forks
source link
issues
Newest
Newest
Most commented
Recently updated
Oldest
Least commented
Least recently updated
QA Report
#36
howlbot-integration[bot]
opened
5 months ago
1
QA Report
#35
howlbot-integration[bot]
opened
5 months ago
2
QA Report
#34
howlbot-integration[bot]
opened
5 months ago
2
QA Report
#33
howlbot-integration[bot]
opened
5 months ago
10
`PreBlocker` is set incorrectly
#32
howlbot-integration[bot]
closed
5 months ago
1
Unhandled type assertion failure in AutoCliOpts function
#31
howlbot-integration[bot]
closed
5 months ago
5
sdk.Context is still used instead of context.Context, causing interface mismatch.
#30
howlbot-integration[bot]
closed
5 months ago
1
Govshuttle's RegisterLegacyAminoCodec is Implemented Incorrectly
#29
howlbot-integration[bot]
closed
5 months ago
5
An attacker can DoS a coinswap pool
#28
howlbot-integration[bot]
opened
5 months ago
3
MsgSwapOrder will never work for Canto nodes
#27
howlbot-integration[bot]
opened
5 months ago
7
Price manipulation in `coinswap::pool`
#26
howlbot-integration[bot]
opened
5 months ago
4
A malicious pool creator or first depositor can make depositing and removing liquidity unfavorable for other users.
#25
howlbot-integration[bot]
opened
5 months ago
2
Malicious First depositor can DOSed the add liquidity function in coinswap module
#24
howlbot-integration[bot]
opened
5 months ago
2
Several Inconsistencies in `app.go` from cosmos 0.5.x upgrade
#23
howlbot-integration[bot]
closed
5 months ago
1
tmbytes.HexBytes is not changed to []bytes cause incorrect interface GetDenomTrace implementation
#22
howlbot-integration[bot]
closed
5 months ago
3
upgradetypes.ModuleName has been mistakenly added to SetOrderBeginBlockers
#21
howlbot-integration[bot]
closed
5 months ago
3
DoS vulnerability in `coinswap` pool
#20
howlbot-integration[bot]
closed
5 months ago
4
OnRecvPacket can lead to loss of funds when swapping and converting due to lack of rollback/poor error handling
#19
howlbot-integration[bot]
opened
5 months ago
9
`context.Context` should be used everywhere instead of `sdk.Context`. This can lead to incorrect interfaces.
#18
howlbot-integration[bot]
closed
5 months ago
3
Wrong address prefix for ethermint bech32 account leads to inability to authorize users
#17
howlbot-integration[bot]
opened
5 months ago
4
Panic in MustUnmarshal
#16
howlbot-integration[bot]
closed
5 months ago
3
Oppornity to drain funds because of missing propId validaiton in govshuttle
#15
howlbot-integration[bot]
opened
5 months ago
6
Protocol uses deprecated library
#14
c4-bot-6
closed
5 months ago
3
`coinswap` liquidity pool susceptible to inflation attacks
#13
c4-bot-3
opened
5 months ago
6
QA Report
#12
c4-bot-2
opened
5 months ago
4
Canto-main v8 upgrade discards the "IBC transfers" module parameters
#11
c4-bot-9
closed
5 months ago
3
blockedAddrs can bypass
#10
c4-bot-6
opened
5 months ago
4
Govshuttle module does not register it messages to LegacyAminoCodec
#9
c4-bot-6
closed
5 months ago
3
Govshuttle module does not register the "MsgUpdateParams" on the SDK registry
#8
c4-bot-3
closed
5 months ago
5
coinswap pool price manipulation
#7
c4-bot-7
closed
5 months ago
5
coinswap pool can be DoS
#6
c4-bot-1
closed
5 months ago
2
Govshuttle module does not register its transaction MsgServer
#5
c4-bot-5
opened
5 months ago
5
Incomplete "cosmos.msg.v1.signer" protobuf annotation causes the "MsgSwapOrder" message to fail
#4
c4-bot-6
closed
5 months ago
3
OnRecvPacket does not roll back failures in Convert coins or Swap coins
#3
c4-bot-4
closed
5 months ago
2
Incorrect names provided in `RegisterConcrete` calls break LegacyAmino signing method
#2
c4-bot-7
opened
5 months ago
5
Agreements & Disclosures
#1
code4rena-id[bot]
opened
6 months ago
0