Skip to content
This repository was archived by the owner on Jan 26, 2025. It is now read-only.

Issues: sherlock-audit/2024-07-exactly-stacking-contracts-judging

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Assignee
Filter by who’s assigned
Sort

Issues list

0uts1der - Precision Loss in notifyRewardAmount Function Causes Unclaimable RewardToken Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#96 opened Jul 25, 2024 by sherlock-admin4
0x73696d616f - Some bad debt will not be cleared when it should which will cause accrual of bad debt decreasing the protocol's solvency Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Won't Fix The sponsor confirmed this issue will not be fixed
#74 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Liquidator will leave a pool with unassigned earnings on Market::clearBadDebt() free to claim for anyone when the repaid maturity is not the last Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#73 opened Jul 25, 2024 by sherlock-admin3
0x73696d616f - Liquidations will leave dust when repaying expired maturities, making it impossible to clear bad debt putting the protocol at a risk of insolvency Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Won't Fix The sponsor confirmed this issue will not be fixed
#69 opened Jul 25, 2024 by sherlock-admin3
sakshamguruji - Rewards Can Be Harvested Even When Distribution Is Marked As Finished Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#66 opened Jul 25, 2024 by sherlock-admin4
0x73696d616f - Liquidating maturies with unassigned earnings will not take into account floating assets increase leading to loss of funds Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Won't Fix The sponsor confirmed this issue will not be fixed
#64 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Having no deposits in StakedEXA will lead to stuck rewards when harvesting Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#48 opened Jul 25, 2024 by sherlock-admin4
0x73696d616f - Anyone will DoS setting a new rewards duration which harms the protocol/users as they will receive too much or too little rewards Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#46 opened Jul 25, 2024 by sherlock-admin3
0x73696d616f - Market utilization ratio near 100% will DoS deposits as harvest tries to withdraw and reverts Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#45 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Setting a new market will make depositing to the market impossible when harvesting, DoSing deposits Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#41 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Frozen/paused Market that is harvested from in StakedEXA will DoS deposits leading to loss of yield Escalation Resolved This issue's escalations have been approved/rejected Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#35 opened Jul 25, 2024 by sherlock-admin2
0x73696d616f - Attackers will reset avgStart of any user making rewards stuck for longer and get lost to savings Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#22 opened Jul 25, 2024 by sherlock-admin3
0x73696d616f - Depositing to another receiver othan than msg.sender will lead to stuck funds by increasing avgStart without claiming Escalation Resolved This issue's escalations have been approved/rejected Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A Medium severity issue. Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#21 opened Jul 25, 2024 by sherlock-admin2
ProTip! Updated in the last three days: updated:>2025-04-12.