issues
search
sherlock-audit
/
2024-02-jala-swap-judging
6
stars
4
forks
source link
issues
Newest
Newest
Most commented
Recently updated
Oldest
Least commented
Least recently updated
aman - Unnecessary call to `_transfer` function inside `ChilizWrappedERC20:withdrawTo` will leads to gas Griefing
#209
sherlock-admin2
closed
6 months ago
1
hunter_w3b - `JalaPair.sol::_safeTransfer` function does not check for the existence of the ERC20 token contract
#208
sherlock-admin
closed
6 months ago
1
MatricksDeCoder - Code Injection Via Token Name
#207
sherlock-admin2
closed
6 months ago
1
0xRstStn - ```_update``` function in ```JalaPair.sol``` will revert when ```priceCumulativeLast```overflows
#206
sherlock-admin
closed
6 months ago
0
MatricksDeCoder - Protocol may not work with upgradeable tokens
#205
sherlock-admin2
closed
6 months ago
0
MatricksDeCoder - Protocol may not work with upgradeable tokens
#204
sherlock-admin
closed
6 months ago
0
DenTonylifer - Loss of funds due to incorrect rounding
#203
sherlock-admin2
closed
6 months ago
1
MatricksDeCoder - Unchecked return value of approve for ChilizWrapperFactory.sol transfers
#202
sherlock-admin
closed
6 months ago
0
MatricksDeCoder - Unchecked return value of approve
#201
sherlock-admin2
closed
6 months ago
0
MatricksDeCoder - Protocol may not work with tokens that dont use name, decimals, symbol
#200
sherlock-admin
closed
6 months ago
0
bareli - wrong implement of 'depositFor' and 'withdrawTo'
#199
sherlock-admin2
closed
6 months ago
1
santiellena - `permit` function not implemented on `JalaPair`
#198
sherlock-admin
closed
6 months ago
0
santiellena - `ChilizWrappedERC20` is vulnerable to address collision
#197
sherlock-admin2
closed
5 months ago
2
santiellena - `JalaPair::_update` reverts due to underflow
#196
sherlock-admin
closed
6 months ago
0
aman - `JalaMasterRouter::wrapTokenAndaddLiquidityETH` is vulnerable to reentrancy attack
#195
sherlock-admin2
closed
6 months ago
6
alymurtazamemon - Missing Validation of `create2` return value.
#194
sherlock-admin
closed
6 months ago
1
bareli - wrong implementation of 'unwrap'
#193
sherlock-admin2
closed
6 months ago
1
alymurtazamemon - `ChilizWrapperERC20` contract is dependent on optional methods of EIP20 standard.
#192
sherlock-admin
closed
6 months ago
0
Arabadzhiev - In `JalaMasterRouter::swapExactTokensForETH` the `amountIn` value is not being scaled up when performing the wrapped token swap call to `JalaRouter02::swapExactTokensForETH`
#191
sherlock-admin2
closed
6 months ago
0
0xC - `abi.encodePacked` Allows Hash Collision
#190
sherlock-admin
closed
6 months ago
0
honeymewn - Functions using permit scheme can be DoSed
#189
sherlock-admin2
closed
6 months ago
0
jah - user losses there funds due to forgotten calculation
#188
sherlock-admin
closed
6 months ago
0
Spearmint - Centralization risk
#187
sherlock-admin2
closed
6 months ago
0
fibonacci - JalaPair potential permanent DoS due to overflow
#186
sherlock-admin
opened
6 months ago
19
b0g0 - Permit functions inside JalaRouter02 will not work
#185
sherlock-admin2
closed
6 months ago
0
0x996 - Due to precision loss, it is impossible to correctly calculate `tokenAReturnAmount`, `tokenBReturnAmount`, `tokenReturnAmount`, and `tokenOutReturnAmount`.
#184
sherlock-admin
closed
6 months ago
1
Norah - Attacker can invalidate all the initial `removeLiquidityWithPermit()` transactions.
#183
sherlock-admin2
closed
6 months ago
0
b0g0 - Slippage protection will not work when removing liquidity through JalaMasterRouter
#182
sherlock-admin
closed
6 months ago
0
0xlucky - Functions with permit functionallity can be greived ( DOS )
#181
sherlock-admin2
closed
6 months ago
0
Afriaudit - The protocol is constrained in its ability to interact with a significant number of tokens.
#180
sherlock-admin
closed
6 months ago
0
deepplus - Since `kLast` is updated after updating current reserves, `_mintFee` function of `JalaPair` cannot mint fee tokens.
#179
sherlock-admin2
closed
5 months ago
2
jokr - Permit is supported by `JalaRouter02` not implemented in `JalaERC20`
#178
sherlock-admin
closed
6 months ago
0
jokr - Permit functions in router can be affected by Dos
#177
sherlock-admin2
closed
5 months ago
13
jokr - `JalaPair.swap` doesn’t check if fee is enabled
#176
sherlock-admin
closed
6 months ago
1
Nyxaris - Potential manipulation of liquidity pools due to tokens with arbitrary minting capabilities.
#175
sherlock-admin2
closed
6 months ago
0
jokr - Minting fees to `DEAD` address
#174
sherlock-admin
closed
5 months ago
1
WangAudit - `JalaPair::mint` migrators can mint as much as `type(uint).max - 1` and DOS the pair contract.
#173
sherlock-admin2
closed
6 months ago
0
jokr - `ChilizWrappedERC20.Initialize` will revet if underlying token decimals is 18
#172
sherlock-admin
closed
6 months ago
0
Nyxaris - Potential for Front-Running and Sandwich Attacks due to Low amountOutMin in swapExactTokensForTokens
#171
sherlock-admin2
closed
6 months ago
1
ECunha - Rounding error causing user to loose funds
#170
sherlock-admin
closed
6 months ago
1
WangAudit - `JalaPair::_mintFee` if `feeToSetter` decides to stop accrueing fees, sets `feeTo` to address(0), then we turn the fees back on, they will not accrue on the first liquidity event
#169
sherlock-admin2
closed
6 months ago
1
ECunha - `JalaPair::_safeTransfer` function has a misleading name
#168
sherlock-admin
closed
6 months ago
1
Praise03 - Token Transfers from non-existent contracts will always be overlooked due to lack of contract existence checks
#167
sherlock-admin2
closed
6 months ago
0
ECunha - Unbounded array can provoke a DoS attack
#166
sherlock-admin
closed
6 months ago
1
WangAudit - `JalaPair::_mintFee` incorrect check for `feeTo` address leads to minting unecessary fees
#165
sherlock-admin2
closed
6 months ago
0
Nyxaris - Token Truncation in Liquidity Removal
#164
sherlock-admin
closed
6 months ago
1
Nyxaris - Potential for Rounding Exploit in Fee Distribution Mechanism
#163
sherlock-admin2
closed
6 months ago
1
fugazzi - JalaMasterRouter fails to scale minumum output amounts to wrapped units
#162
sherlock-admin
closed
6 months ago
6
fugazzi - Flash loan users will have to pay fees twice
#161
sherlock-admin2
closed
6 months ago
0
fugazzi - Big flash loans will fail due to fee
#160
sherlock-admin
closed
5 months ago
2
Previous
Next