issues
search
sherlock-audit
/
2024-01-napier-judging
9
stars
6
forks
source link
issues
Newest
Newest
Most commented
Recently updated
Oldest
Least commented
Least recently updated
xiaoming90 - Benign esfrxETH holders incur more loss than expected
#82
sherlock-admin2
opened
7 months ago
7
xiaoming90 - `swapUnderlyingForPt` does not sweep the remaining unused ETH back to users
#81
sherlock-admin
closed
7 months ago
2
xiaoming90 - YT holder are unable to claim their interest
#80
sherlock-admin2
opened
7 months ago
12
xiaoming90 - Users who claimed more frequently received lesser yield
#79
sherlock-admin
closed
7 months ago
3
ydlee - The NapierPool does not charge swap fees when swapping underlying asset for Pt or BaseLpt.
#78
sherlock-admin2
closed
7 months ago
12
vvv - Attacker can approve any transfers from NapierRouter to arbitrary addresses
#77
sherlock-admin
closed
7 months ago
0
Solidity_ATL_Team_1 - Fund loss when calling `swapUnderlyingForPt` as excess ETH isn't refunded automatically
#76
sherlock-admin2
closed
7 months ago
1
Solidity_ATL_Team_1 - Missing whenNotPaused modifiers in tranche `Redeemwithyt`,`redeem`, and `withdraw`
#75
sherlock-admin
closed
7 months ago
1
Rhaydden - Potential ERC20 Token Approval Issue in PeripheryPayments Contract
#74
sherlock-admin2
closed
7 months ago
0
mahdikarimi - Attacker can DoS redeeming of PT and YT tokens
#73
sherlock-admin
closed
7 months ago
10
jah - wrong logic when calculating a fee
#72
sherlock-admin2
closed
7 months ago
1
DenTonylifer - Missing zero amount check may lead to loss of funds
#71
sherlock-admin
closed
7 months ago
3
DenTonylifer - Not updating "gscales" in Tranche.sol
#70
sherlock-admin2
closed
7 months ago
0
Arcanet - No Slippage Protection Spawing UT for YT
#69
sherlock-admin
closed
7 months ago
1
zhuying - The slippage check in ```removeLiquidity``` function can be bypassed by donating liquidity directly to the napier pool
#68
sherlock-admin2
closed
7 months ago
1
Hajime - Attacker can mint more shares when calling the `BaseLSTAdapter.prefundedDeposit()`
#67
sherlock-admin
closed
7 months ago
0
Arcanet - No Slippage Protection Spawing YT for UT
#66
sherlock-admin2
closed
7 months ago
1
zhuying - ```tricrypto.add_liquidity``` in ```swapPtForUnderlying``` function doesn't have right parameter and won't work
#65
sherlock-admin
closed
7 months ago
1
FastTiger - As frontrunning occurs, the protocol suffers a loss of funds.
#64
sherlock-admin2
closed
7 months ago
0
FastTiger - Due to rounding error, Users suffer losses.
#63
sherlock-admin
closed
7 months ago
1
FastTiger - Due to rounding error, the user receives a smaller amount of underlying asset back.
#62
sherlock-admin2
closed
7 months ago
1
FastTiger - In `TrancheRouter.sol#issue` function, don't set amount of tokens as allowance of this contract over the caller's token.
#61
sherlock-admin
closed
7 months ago
1
KingNFT - Grief attack on ````Tranche.issue()```` to make users losing partial profit
#60
sherlock-admin2
closed
7 months ago
2
Bandit - Attacker Can Trigger Lido Staking Limit To Steal Lido Eth Tranche Deposit Attempts
#59
sherlock-admin
closed
7 months ago
14
Nyxaris - H-0 Potential Front-Running Vulnerability in addLiquidity Function
#58
sherlock-admin2
closed
7 months ago
0
Bandit - Share Inflation For Base LST Adapter
#57
sherlock-admin
closed
7 months ago
1
Bandit - Scale calculation rounds in favor of user during withdraw
#56
sherlock-admin2
closed
7 months ago
16
Bandit - Missing stETH conversion
#55
sherlock-admin
closed
7 months ago
1
Bandit - `minLiquidity` does not protect from curve triCryptoPool liquidity sandwiching
#54
sherlock-admin2
closed
7 months ago
1
AuditorPraise - SFrxETHAdapter._stake() fails to check if `submit` is paused for frxETHMinter.
#53
sherlock-admin
closed
7 months ago
1
Arcanet - No Slippage Protection
#52
sherlock-admin2
closed
7 months ago
1
Solidity_ATL_Team_2 - Napier pool owner can unfairly increase protocol fees on swaps to earn more revenue
#51
sherlock-admin
opened
7 months ago
13
jennifer37 - incorrect allowance check in NapierRouter::removeLiquidityOneUnderlying()
#50
sherlock-admin2
closed
6 months ago
9
jennifer37 - Missing refund left ether to users in swapUnderlyingForPt()
#49
sherlock-admin
closed
7 months ago
1
jennifer37 - Incorrect rounding direction in Tranche::withdraw()
#48
sherlock-admin2
closed
7 months ago
13
jennifer37 - Vault inflation attack in StEtherAdapter::prefundedDeposit()
#47
sherlock-admin
closed
7 months ago
1
jennifer37 - maxScale cannot be updated correctly after maturity
#46
sherlock-admin2
closed
7 months ago
0
jennifer37 - Missing compute target belongs to YT in Tranche::redeemWithYT()
#45
sherlock-admin
closed
7 months ago
2
AuditorPraise - Tranche.issue() may revert @ `adapter.prefundedDeposit()` Ln if adapter is RETH Adapter.
#44
sherlock-admin2
closed
7 months ago
1
0xepley - Insufficient Slippage Protection in Stake Function
#43
sherlock-admin
closed
7 months ago
1
0xBhumii - Missing Zero Address Check for `Rebalancer` in `BaseLSTAdapter` Contract
#42
sherlock-admin2
closed
7 months ago
0
0xBhumii - Missing zero address validation for `Management` in the `constructor` of `TrancheFactory` contract
#41
sherlock-admin
closed
7 months ago
1
0xBhumii - Immutable `Management` Address in `TrancheFactory` Contract
#40
sherlock-admin2
closed
7 months ago
1
0xBhumii - Missing Check for Zero `Underlying` Amount in `Issue` function
#39
sherlock-admin
closed
7 months ago
0
0xBhumii - Inaccurate Calculation of Token Amounts in `removeLiquidity` Function
#38
sherlock-admin2
closed
7 months ago
0
st0yanov - Shares could be lost and assets stolen with prefunded redemptions to children of `BaseLSTAdapter`
#37
sherlock-admin
closed
7 months ago
0
st0yanov - Prefunded deposits to children of `BaseLSTAdapter` could be lost and shares stolen
#36
sherlock-admin2
closed
7 months ago
2
crypticdefense - Swapping underlying for yield tokens is susceptible to precision loss
#35
sherlock-admin
closed
7 months ago
1
crypticdefense - User can drain pools that use tokens with multiple addresses
#34
sherlock-admin2
closed
7 months ago
1
crypticdefense - Rebasing tokens go to the fee recipient
#33
sherlock-admin
closed
7 months ago
1
Previous
Next