issues
search
sherlock-audit
/
2024-05-napier-update-judging
8
stars
7
forks
source link
issues
Newest
Newest
Most commented
Recently updated
Oldest
Least commented
Least recently updated
Missing check for zero address
#96
sherlock-admin3
closed
2 months ago
0
Wrong percentage calculation
#95
sherlock-admin3
closed
2 months ago
0
add zero address validation in constructor
#94
sherlock-admin3
closed
2 months ago
0
Wrong comment on function _stake
#93
sherlock-admin4
closed
2 months ago
0
Albort - When executing RenzoAdapter::_stake(), sending RswETH to the contract might cause the final check to fail.
#92
sherlock-admin4
closed
2 months ago
1
Albort - When executing RswETHAdapter::_stake(), sending RswETH to the contract might cause the final check to fail.
#91
sherlock-admin3
closed
2 months ago
1
w42d3n - Re-entrancy Vulnerabilities in BaseLSTAdapter
#90
sherlock-admin3
closed
2 months ago
3
w42d3n - Lack of ETH Handling
#89
sherlock-admin3
closed
2 months ago
1
zzykxx - `RsETHAdapter` adapter `_stake()` function lacks slippage control
#88
sherlock-admin3
closed
2 months ago
9
bareli - Unchecked ERC20 transfers can cause lock up
#87
sherlock-admin3
closed
2 months ago
1
KungFuPanda - When there's a protocol-specific limit of the underlyingAmount that can be supplied through a single deposit, the remainder of the underlyingAmount that was charged from the user is not sent back to the user
#86
sherlock-admin3
closed
2 months ago
6
zzykxx - `_stake()` function in `RenzoAdaper` and `RsETHAdapter` doesn't check if max TVL is reached
#85
sherlock-admin2
closed
2 months ago
0
0xrobsol - Transfer and Flash Loan Repayment Safety Issue
#84
sherlock-admin4
closed
2 months ago
1
no - No slippage check in `swapETHForYt` function can lead to slippage losses during swap
#83
sherlock-admin3
closed
2 months ago
3
PNS - Incorrect staking limit check in `RsETHAdapter`
#82
sherlock-admin2
closed
2 months ago
1
no - Use safeTransferFrom() instead of transferFrom()
#81
sherlock-admin4
closed
2 months ago
1
PNS - `RsETHAdapter` uses an asset price that may not be up-to-date
#80
sherlock-admin3
closed
2 months ago
3
KupiaSec - EETHAdapter.totalAssets() returns wrong value
#79
sherlock-admin2
closed
2 months ago
1
KupiaSec - EETHAdapter.claimWithdrawal() uses a wrong condition and it doesn't work in most cases
#78
sherlock-admin2
closed
2 months ago
0
KupiaSec - MetapoolRouter.swapETHForYt() validates a wrong condition and this blocks intended workflow in most cases
#77
sherlock-admin4
closed
2 months ago
0
KupiaSec - MetapoolRouter.swapETHForPt() reverts due to a typo in a function parameter
#76
sherlock-admin4
closed
2 months ago
1
zzykxx - Kelp adapter won't allow users to deposit if `getAssetCurrentLimit` returns `0`
#75
sherlock-admin3
opened
2 months ago
2
zzykxx - Kelp adapter won't allow users to deposit in some situations
#74
sherlock-admin3
closed
2 months ago
2
KupiaSec - Potential Incompatibility Issue with `PufETHAdapter::_stake` Function
#73
sherlock-admin2
closed
2 months ago
0
Varun_05 - Stake limit is is updated by wrong amount for some cases.
#72
sherlock-admin2
closed
2 months ago
0
Varun_05 - swapETHForYt would always revert due to a wrong check in receiveFlashLoan function.
#71
sherlock-admin4
closed
2 months ago
0
PNS - `PufETHAdapter` use wrong deposit function signature from outdated depositor interface
#70
sherlock-admin4
closed
2 months ago
0
BiasedMerc - RsETHAdapter::_stake() does not have any checks on the amount of RSETH minted during depositETH call
#69
sherlock-admin3
closed
2 months ago
0
karsar - Minimum ETH Withdrawal Requirement Causes Delayed Requests
#68
sherlock-admin3
closed
2 months ago
1
merlin - Issue with staking being paused and LRTDepositPool limit in RsETHAdapter.sol
#67
sherlock-admin2
closed
2 months ago
7
zzykxx - Users can frontrun LSTs/LRTs tokens price increase in order to capture extra value
#66
sherlock-admin2
closed
2 months ago
16
zzykxx - Users can frontrun LSTs/LRTs tokens prices decrease in order to avoid losses
#65
sherlock-admin4
opened
2 months ago
1
zzykxx - Adapters revert when 0 shares are minted, making it impossible to deposit under certain conditions
#64
sherlock-admin4
opened
2 months ago
3
zzykxx - `_stake()` function in `PufEthAdapter` will always revert
#63
sherlock-admin3
closed
2 months ago
0
Drynooo - EEtherAdapter's staking functionality may not be available
#62
sherlock-admin3
closed
2 months ago
1
Drynooo - Funds may not be withdrawn due to a check error
#61
sherlock-admin2
closed
2 months ago
0
Drynooo - The revert of _stake will cause many functions of the protocol to be unavailable.
#60
sherlock-admin2
closed
2 months ago
1
Drynooo - In the RsETHAdapter contract, _stake may revert
#59
sherlock-admin4
closed
2 months ago
1
Drynooo - Wrong checking causes the swapETHForYt function to revert with a high probability
#58
sherlock-admin3
closed
2 months ago
0
Drynooo - The _stake function in the PufETHAdapter contract will revert
#57
sherlock-admin3
closed
2 months ago
0
merlin - UniETHAdapter and RsETHAdapter do not have slippage protection
#56
sherlock-admin2
closed
2 months ago
2
merlin - DOS in the claimWithdraw function due to an incorrect check of the lastFinalizedRequestId in the EEtherAdapter.sol
#55
sherlock-admin2
opened
2 months ago
2
merlin - DOS vulnerability in the _stake function in RsETHAdapter.sol
#54
sherlock-admin4
closed
1 month ago
22
ZanyBonzy - Lack of slippage control during staking in bedrock
#53
sherlock-admin4
closed
2 months ago
5
karsar - PufETHAdapter fails when trying to stake stETH
#52
sherlock-admin3
closed
2 months ago
0
merlin - PufETHAdapter has not implemented withdrawal functions
#51
sherlock-admin3
closed
2 months ago
1
merlin - The scenario where the buffer in RsETHAdapter can be much larger than expected
#50
sherlock-admin2
closed
2 months ago
6
merlin - The scenario where the buffer in PufETHAdapter can be much larger than expected
#49
sherlock-admin2
closed
2 months ago
1
merlin - PufETHAdapter does not handle the case when the stakeLimit of stETH is zero correctly
#48
sherlock-admin4
closed
1 month ago
8
no - Checking return share in `_stake()` causes Dos
#47
sherlock-admin2
closed
2 months ago
1
Next