Skip to content

Issues: sherlock-audit/2024-07-exactly-stacking-contracts-judging

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Assignee
Filter by who’s assigned
Sort

Issues list

0uts1der - Precision Loss in notifyRewardAmount Function Causes Unclaimable RewardToken Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#96 opened Jul 25, 2024 by sherlock-admin4
0x73696d616f - Some bad debt will not be cleared when it should which will cause accrual of bad debt decreasing the protocol's solvency Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Won't Fix The sponsor confirmed this issue will not be fixed
#74 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Liquidator will leave a pool with unassigned earnings on Market::clearBadDebt() free to claim for anyone when the repaid maturity is not the last Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#73 opened Jul 25, 2024 by sherlock-admin3
0x73696d616f - Liquidations will leave dust when repaying expired maturities, making it impossible to clear bad debt putting the protocol at a risk of insolvency Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Won't Fix The sponsor confirmed this issue will not be fixed
#69 opened Jul 25, 2024 by sherlock-admin3
sakshamguruji - Rewards Can Be Harvested Even When Distribution Is Marked As Finished Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#66 opened Jul 25, 2024 by sherlock-admin4
0x73696d616f - Liquidating maturies with unassigned earnings will not take into account floating assets increase leading to loss of funds Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Won't Fix The sponsor confirmed this issue will not be fixed
#64 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Having no deposits in StakedEXA will lead to stuck rewards when harvesting Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#48 opened Jul 25, 2024 by sherlock-admin4
0x73696d616f - Anyone will DoS setting a new rewards duration which harms the protocol/users as they will receive too much or too little rewards Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#46 opened Jul 25, 2024 by sherlock-admin3
0x73696d616f - Market utilization ratio near 100% will DoS deposits as harvest tries to withdraw and reverts Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#45 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Setting a new market will make depositing to the market impossible when harvesting, DoSing deposits Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#41 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Frozen/paused Market that is harvested from in StakedEXA will DoS deposits leading to loss of yield Escalation Resolved This issue's escalations have been approved/rejected Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#35 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Attackers will reset avgStart of any user making rewards stuck for longer and get lost to savings Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#22 opened Jul 25, 2024 by sherlock-admin3
0x73696d616f - Depositing to another receiver othan than msg.sender will lead to stuck funds by increasing avgStart without claiming Escalation Resolved This issue's escalations have been approved/rejected Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#21 opened Jul 25, 2024 by sherlock-admin2
ProTip! Updated in the last three days: updated:>2024-10-23.