For more info, visit: https://decentra.vision/
Begin month | Project | Category | Provider | Duration | Platform |
---|---|---|---|---|---|
2024-11 | Near One OmniProtocol | Cross-chain, Asset bridging | AuditOne | 2.0 weeks | Rust / NEAR, Rust / Solana, Solidity / EVM |
2024-11 | To be disclosed | Combinatorial prediction markets | Oak Security | 2.5 weeks | Rust / Substrate |
2024-11 | Push Protocol - Comm Cairo / Rust | Cross-chain, Notifications | Oak Security | 1.0 weeks | Cairo / Starknet, Rust / Solana |
2024-10 | BugHole Restaking | Kaia chain, Restaking | Trust Security | 0.6 weeks | Solidity / EVM |
2024-10 | Level Money | Stablecoin, Restaking | Spearbit | 1.0 weeks | Solidity / EVM |
2024-10 | To be disclosed | DEX, Aggregator | Code4rena Zenith | 0.4 weeks | Rust / Solana |
2024-10 | 4Real Finance | Treasury, Staking, Yield | Code4rena Zenith | 0.8 weeks | Rust / Solana |
2024-10 | To be disclosed | DEX, Aggregator | Code4rena Zenith | 0.3 weeks | Rust / Solana |
2024-10 | Near One OmniBridge | Cross-chain, Asset bridging | AuditOne | 2.0 weeks | Rust / NEAR, Solidity / EVM |
2024-09 | Balancer V3 | AMM, DEX, Vault | Spearbit | 4.0 weeks | Solidity / EVM |
2024-08 | Resolv | Stablecoin, Liquid staking, Futures | Pashov Audit Group | 1.0 weeks | Solidity / EVM |
2024-08 | Aurora BTC Light Client | Bitcoin client, Relay | AuditOne | 1.0 weeks | Rust / NEAR |
2024-07 | Undisclosed | Proof of Liquidity, Staking, Voting | Spearbit | 3.0 weeks | Solidity / EVM |
2024-06 | Router Protocol | Cross-chain, Liquidity, Messaging | Oak Security | 3.0 weeks | Rust / Solana |
2024-06 | Out GCC | Tokenization, Marketplace | Oak Security | 1.0 weeks | Rust / Solana |
2024-06 | Sharwa Finance | Margin trading, Options | Pashov Audit Group | 1.0 weeks | Solidity / EVM |
2024-06 | Undisclosed | Cross-chain, Airdrop | Pashov Audit Group | 0.4 weeks | Solidity / EVM |
2024-05 | Pendle Finance | Tokenization, Yield trading | Spearbit | 3.0 weeks | Solidity / EVM |
2024-04 | Undisclosed | Game, Infrastructure | Oak Security | 1.1 weeks | Rust / Substrate |
Begin month | Project | Category | Provider | Duration | Platform |
---|---|---|---|---|---|
2024-12 | To be disclosed | Lending, Leveraged yield | Spearbit | 1.0 weeks | Solidity / EVM |
2024-07 | Possum Core (ref) | Governance, Staking | Decentra Vision | 0.8 weeks | Solidity / EVM |
2024-06 | Proportionalized Contracts | Fee token, Staking | Decentra Vision | 0.8 weeks | Solidity / EVM |
2024-05 | Yeet Cup | Game, Yield | Shieldify | 0.8 weeks | Solidity / EVM |
2024-03 | Olas Lockbox v2 - Mitigation review | Liquidity bonding | Cantina | 0.4 weeks | Rust / Solana |
2024-03: Possum Labs Portals v2 🥈
Risk | Title | Finding in report |
---|---|---|
🟨 Medium |
Investors could earn 10x more than intended | M-01 |
🟦 Low |
Cannot revoke permit of MintBurnToken | L-02 |
2024-02: Ion Protocol 🥇
Risk | Title | Finding in report |
---|---|---|
🟨 Medium |
Unsafe downcast truncation in UniswapOracleLibrary leading to invalid price data | M-01 |
- 2024-07: BendDAO Invitational
- 2024-05: Lavarage Appellate Court
- 2024-03: Neobase Invitational
- 2024-02: Code4rena Blue Bug Bounty submissions (undisclosed)
- 2024-02: UniStaker Infrastructure
- 2023-12: Revolution Protocol
- 2023-11: Canto Application Specific Dollars and Bonding Curves for 1155s
- 2023-10: The Wildcat Protocol
2024-03: Acala
Rust / Substrate
Risk | Title | Selected for report |
---|---|---|
🟨 Medium |
Incentive accumulation can be sandwiched with additional shares to gain advantage over long-term depositors | M-02 |
2024-03: Canto Invitational 🥈
2024-03: Phat Contract Runtime 🥉
Rust / Substrate
Related tweet
Awards have been announced for the $60,500 USDC @PhalaNetwork audit! 🥳
— Code4rena (@code4rena) April 1, 2024
Top 5:
🥇 @DadeKuma - $15,937.95 USDC
🥈 zhaojie - $15,225.87 USDC
🥉 @MarioPoneder - $12,619.42 USDC
🏅 Koolex - $2,606.45 USDC
🏅 Cryptor - $994.09 USDC pic.twitter.com/C15fmXxxJ2
Risk | Title | Selected for report |
---|---|---|
🟨 Medium |
Limited availability of balance_of(...) method | M-01 |
2024-01: Opus 🥉
Cairo / Starknet
Related tweet
Rounding out the Top 3 was @MarioPoneder! 🥉
— Code4rena (@code4rena) March 6, 2024
Rank: #3 (#86 All-time)
Medium-risk findings: 2 (2 solo) pic.twitter.com/vCgs0GlnQY
Risk | Title | Selected for report |
---|---|---|
🟨 Medium |
Collateral cannot be withdrawn from trove once yang is suspended | M-07 |
🟨 Medium |
Unhealthy troves with LTV > 90% cannot always be absorbed as intended | M-09 |
🟦 Low |
Low Risk and Non-Critical Issues | QA |
2023-12: Olas
Risk | Title |
---|---|
🟥 High |
Bonds created in year cross epoch’s can lead to lost payouts |
2023-10: zkSync Era
2023-09: Maia DAO - Ulysses
Risk | Title | Selected for report |
---|---|---|
🟥 High |
All tokens can be stolen from VirtualAccount due to missing access modifier | H-01 |
2023-09: Venus Prime
Risk | Title |
---|---|
🟥 High |
Prime contract incompatible with currently deployed / active markets (vToken) with 8 decimals |
🟥 High |
Prime contract incompatible with underlying assets differing from 18 decimals |
2023-08: Chainlink Staking v0.2
Findings under NDA, requires Code4rena backstage access.
Risk | Title |
---|---|
🟨 Medium |
#223 |
2023-08: Dopex
Risk | Title |
---|---|
🟨 Medium |
SecurityCouncilNomineeElectionGovernorTiming.electionToTimestamp(...) can create unsupported/invalid dates |
2023-07: Tapioca DAO
2023-07: Axelar Network
Risk | Title | Selected for report |
---|---|---|
🟨 Medium |
Insufficient support for tokens with different decimals on different chains lead to loss of funds on cross-chain bridging | M-08 |
2023-05: Maia DAO Ecosystem
Findings under NDA, requires Code4rena backstage access.
Risk | Title |
---|---|
🟥 High |
#164 |
🟨 Medium |
#95 |
🟨 Medium |
#307 |
2023-05: Ajna Protocol
Risk | Title | Selected for report |
---|---|---|
🟥 High |
Position NFT can be spammed with insignificant positions by anyone until rewards DoS | H-03 |
🟥 High |
Permanent loss of rewards on temporary underfunding of RewardsManager contract |
2023-04: EigenLayer 🥇
Related tweet
Awards have been announced for the $90,500 USDC @eigenlayer audit 🤝
— Code4rena (@code4rena) June 10, 2023
Top 5:
🥇 @MarioPoneder - $13,081.90 USDC
🥈 volodya - $12,193.66 USDC
🥉 windowhan001 - $5,031.50 USDC
🏅 @CyfrinAudits - $3,177.34 USDC
🏅 @QiuhaoLi - $2,972.95 USDC
Risk | Title | Selected for report |
---|---|---|
🟥 High |
Slot and block number proofs not required for verification of withdrawal (multiple withdrawals possible) | H-01 |
2023-04: Rubicon v2
Findings under NDA, requires Code4rena backstage access.
Risk | Title |
---|---|
🟥 High |
#1214 |
🟥 High |
#1265 |
2023-04: Caviar Private Pools
Risk | Title |
---|---|
🟥 High |
Owner of PrivatePool can steal any NFTs and tokens that the pool has approval for |
🟨 Medium |
PrivatePool creation can be front-run |
2023-02: Ethos Reserve
- 2024-09: Centrifuge
2024-02: 3DNS
2024-01: Olas Lockbox 🥈
Rust / Solana
Related tweet
Congratulations to our resident rustaceans on an excellent job during the @autonolas security competition.
— Cantina 🪐 (@cantinaxyz) March 18, 2024
Here are your top 3 placements:
🥇: @99crits - $22,275.61
🥈: @MarioPoneder - $8,590.35
🥉: @meltedblocks - $6,682.68
Full Results Below! pic.twitter.com/Cr5ATXONbQ
2023-11: Superform
2023-11: Morpho Blue
Risk | Title |
---|---|
🟦 Low |
Interest/fee accrual can be suppressed in regular markets with low-decimal loan tokens |
🟦 Low |
Oracles should be whitelisted to avoid theft by direct price manipulation |
Note that I am also listing issues here which were labeled as Excluded
due to the strict High
/Medium
only policy at Sherlock.
However, those issues are still valid & valuable for the sponsor and most of them contain a coded PoC, therefore they might be a good read for new aspiring auditors.
2023-07: Perennial V2
Risk | Title |
---|---|
🟦 Low |
DSU token balance of MultiInvoker contract can be drained by anyone |