-
Notifications
You must be signed in to change notification settings - Fork 0
Issues: code-423n4/2024-10-loopfi-validation
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. Weβll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Treasury contract allows unrestricted access to release funds, enabling premature depletion
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
π€_primary
AI based primary recommendation
π€_11_group
AI based duplicate group recommendation
sufficient quality report
This report is of sufficient quality
#87
opened Oct 18, 2024 by
c4-bot-8
Accumulated rewards would be frozen when the token's index is Assets can be stolen/lost/compromised directly
bug
Something isn't working
π€_primary
AI based primary recommendation
sufficient quality report
This report is of sufficient quality
0
3 (High Risk)
#72
opened Oct 17, 2024 by
c4-bot-8
Core interactions would still be accessible after protocol pause
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
π€_primary
AI based primary recommendation
sufficient quality report
This report is of sufficient quality
#71
opened Oct 17, 2024 by
c4-bot-8
Some residual recipients would now have their residues stuck in Assets can be stolen/lost/compromised directly
bug
Something isn't working
π€_primary
AI based primary recommendation
sufficient quality report
This report is of sufficient quality
SwapAction
after swap
3 (High Risk)
#69
opened Oct 17, 2024 by
c4-bot-3
Liquidity pool is not adjusting the interest rate on healthy repayment profit, which results in incorrect rates
3 (High Risk)
Assets can be stolen/lost/compromised directly
bug
Something isn't working
edited-by-warden
π€_primary
AI based primary recommendation
sufficient quality report
This report is of sufficient quality
#66
opened Oct 17, 2024 by
c4-bot-3
When adding new quoted tokens, worse off rates for Loopfi is always used for all types of tokens
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
π€_primary
AI based primary recommendation
sufficient quality report
This report is of sufficient quality
#34
opened Oct 15, 2024 by
c4-bot-6
modifyCollateralAndDebt()
doesn't work as intended when the vault is paused since debts can still be increased
2 (Med Risk)
#32
opened Oct 15, 2024 by
c4-bot-6
SwapAction's newly implemented Kyber swaps lack slippage protection
3 (High Risk)
Assets can be stolen/lost/compromised directly
bug
Something isn't working
π€_13_group
AI based duplicate group recommendation
sufficient quality report
This report is of sufficient quality
#29
opened Oct 15, 2024 by
c4-bot-3
kyberSwap
will not work due to incorrectly decoded returned swap values
2 (Med Risk)
#24
opened Oct 15, 2024 by
c4-bot-9
Incompatibility Between Solidity Version Pragma and Custom Error Syntax in Locking.sol
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
π€_primary
AI based primary recommendation
sufficient quality report
This report is of sufficient quality
#14
opened Oct 13, 2024 by
c4-bot-6
Rewards might be lost due to the error that _updateRewardIndex() might advance lastBalance without advancing index for a token.
3 (High Risk)
Assets can be stolen/lost/compromised directly
bug
Something isn't working
π€_06_group
AI based duplicate group recommendation
sufficient quality report
This report is of sufficient quality
#12
opened Oct 13, 2024 by
c4-bot-6
Invalid handling of risdual amount in Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
π€_14_group
AI based duplicate group recommendation
sufficient quality report
This report is of sufficient quality
PositionAction::onCreditFlashLoan
, forcing it to revert
2 (Med Risk)
#6
opened Oct 12, 2024 by
c4-bot-3
Invalid handling of flash loan fees in Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
edited-by-warden
π€_14_group
AI based duplicate group recommendation
sufficient quality report
This report is of sufficient quality
PositionAction::onCreditFlashLoan
, forcing it to always revert
2 (Med Risk)
#4
opened Oct 12, 2024 by
c4-bot-4
ProTip!
Follow long discussions with comments:>50.