Audix_hq (@audix_hq) 's Twitter Profile
Audix_hq

@audix_hq

Audix strengthens your security assessment workflow by analyzing smart contract code to identify heuristics and invariants

ID: 1869422606270550016

linkhttps://linktr.ee/audix_hq calendar_today18-12-2024 16:41:05

82 Tweet

245 Followers

1 Following

Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟱 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Cork Protocol | Cantina 🪐 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-4 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Slippage protection 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: The early redemption function only validates minimum output for

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟱 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Cork Protocol  | <a href="/cantinaxyz/">Cantina 🪐</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-4
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Slippage protection
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: The early redemption function only validates minimum output for
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟲🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit | Cantina 🪐 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-01 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Business logic 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: A blockchain validation function incorrectly returns success

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟲🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit  | <a href="/cantinaxyz/">Cantina 🪐</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-01
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Business logic
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆:  A blockchain validation function incorrectly returns success
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟳 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-03 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Systemic Failures 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can create unlimited reward plans for a small fee, causing

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟳 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way  | @Cantinaxyz
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-03
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Systemic Failures
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can create unlimited reward plans for a small fee, causing
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟴 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit | Cantina 🪐 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-02 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Inadequate validation 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Execution engine's AcceptedPayloadStatus error bypasses

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟴 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit  | <a href="/cantinaxyz/">Cantina 🪐</a>

𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-02
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Inadequate validation
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Execution engine's AcceptedPayloadStatus error bypasses
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟵 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-04 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Systemic Failures 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can halt the entire blockchain by spamming service

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟯𝟵 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way  | @Cantinaxyz
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-04
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Systemic Failures
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can halt the entire blockchain by spamming service
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟬 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit | Cantina 🪐 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-03 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Business logic 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Genesis deposits have predefined indices (0-85) but the deposit

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟬 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit  | <a href="/cantinaxyz/">Cantina 🪐</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-03
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Business logic
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Genesis deposits have predefined indices (0-85) but the deposit
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟭🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-05 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Service delegations store empty bytes instead of actual delegation data,

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟭🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way  | @Cantinaxyz
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-05
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Service delegations store empty bytes instead of actual delegation data,
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟮🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: TermMax | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-01 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Precision Error 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Small annualized interest values get rounded down to zero when calculating

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟮🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: TermMax   | @Cantinaxyz
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-01
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Precision Error
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Small annualized interest values get rounded down to zero when calculating
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟯🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: TermMax | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-02 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: A mapping that tracks bad debt amounts gets overwritten instead of

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟯🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: TermMax   | @Cantinaxyz
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-02
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: A mapping that tracks bad debt amounts gets overwritten instead of
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟰🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: TermMax | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-03 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Frontrunnig 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can front-run a user's borrowing transaction and redirect the

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟰🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: TermMax   | 
@Cantinaxyz

𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-03
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Frontrunnig
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can front-run a user's borrowing transaction and redirect the
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟱🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-06 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Inadequate validation 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can halt the blockchain indefinitely by creating many

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟱🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Milky Way  | @Cantinaxyz
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-06
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Inadequate validation
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: An attacker can halt the blockchain indefinitely by creating many
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟲 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit | Cantina 🪐 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-04 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Inadequate validation 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: A malicious block proposer can forge arbitrary deposits

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟲 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Berachain Beaconkit  | <a href="/cantinaxyz/">Cantina 🪐</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-04
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Inadequate validation
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: A malicious block proposer can forge arbitrary deposits
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟬𝟰𝟳 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Napier | @Cantinaxyz 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-01 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Users can claim disproportionately more external rewards by collecting

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟬𝟰𝟳 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Napier  | @Cantinaxyz
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-01
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Users can claim disproportionately more external rewards by collecting
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟴 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: DESK | Cantina 🪐 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-01 𝗗𝘂𝗽: 0 𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error 𝗣𝗮𝘆𝗼𝘂𝘁: N/A 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: A liquidation system incorrectly applies collateral factors differently to

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟴 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: DESK  | <a href="/cantinaxyz/">Cantina 🪐</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-01
𝗗𝘂𝗽: 0
𝗖𝗮𝘁𝗲𝗴𝗼𝗿𝘆: Accounting error
𝗣𝗮𝘆𝗼𝘂𝘁:  N/A

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: A liquidation system incorrectly applies collateral factors differently to
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟵 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: SEDA Protocol | SHERLOCK 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-01 𝗗𝘂𝗽: 0 𝗣𝗮𝘆𝗼𝘂𝘁: 3,142 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Attacker can steal 25% of first depositor's funds by inflating share value through repeated

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟰𝟵 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: SEDA Protocol  | <a href="/sherlockdefi/">SHERLOCK</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-01
𝗗𝘂𝗽: 0
𝗣𝗮𝘆𝗼𝘂𝘁:  3,142

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Attacker can steal 25% of first depositor's funds by inflating share value through repeated
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟬 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Yieldoor | SHERLOCK 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-02 𝗗𝘂𝗽: 0 𝗣𝗮𝘆𝗼𝘂𝘁: 3,738 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Strategy uses inaccurate slot0 tick instead of actual pool price when setting liquidity positions near

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟬 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Yieldoor  | <a href="/sherlockdefi/">SHERLOCK</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-02
𝗗𝘂𝗽: 0
𝗣𝗮𝘆𝗼𝘂𝘁:  3,738

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Strategy uses inaccurate slot0 tick instead of actual pool price when setting liquidity positions near
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟭 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2 | SHERLOCK 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-03 𝗗𝘂𝗽: 0 𝗣𝗮𝘆𝗼𝘂𝘁: 4,239 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Attacker exploits guaranteed Intent orders to withdraw collateral before fees are applied, creating

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟭 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2 | <a href="/sherlockdefi/">SHERLOCK</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-03
𝗗𝘂𝗽: 0
𝗣𝗮𝘆𝗼𝘂𝘁:  4,239

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Attacker exploits guaranteed Intent orders to withdraw collateral before fees are applied, creating
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟮 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2 | SHERLOCK 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-03 𝗗𝘂𝗽: 0 𝗣𝗮𝘆𝗼𝘂𝘁: 13,422 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Settlement fees are subtracted twice in global calculations but only once locally, creating

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟮 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2  | <a href="/sherlockdefi/">SHERLOCK</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-03
𝗗𝘂𝗽: 0
𝗣𝗮𝘆𝗼𝘂𝘁:  13,422

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Settlement fees are subtracted twice in global calculations but only once locally, creating
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟯 🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2 | SHERLOCK 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-04 𝗗𝘂𝗽: 0 𝗣𝗮𝘆𝗼𝘂𝘁: 6,039 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Expired oracle versions are treated as valid because they inherit previous version's non-zero

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟯 🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2  | <a href="/sherlockdefi/">SHERLOCK</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-04
𝗗𝘂𝗽: 0
𝗣𝗮𝘆𝗼𝘂𝘁:  6,039

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Expired oracle versions are treated as valid because they inherit previous version's non-zero
Audix_hq (@audix_hq) 's Twitter Profile Photo

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟰🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2 | SHERLOCK 𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗: H-03 𝗗𝘂𝗽: 0 𝗣𝗮𝘆𝗼𝘂𝘁: 13,442 𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Empty market updates don't request oracle versions, causing fee and funding calculations to use

🏆 𝗖𝗼𝗻𝘁𝗲𝘀𝘁 𝗕𝘂𝗴 𝗗𝗶𝗴𝗲𝘀𝘁 - 𝗣𝗧𝟱𝟰🏆

𝗖𝗼𝗻𝘁𝗲𝘀𝘁: Perennial V2 | <a href="/sherlockdefi/">SHERLOCK</a>
𝗙𝗶𝗻𝗱𝗶𝗻𝗴 𝗜𝗗:  H-03
𝗗𝘂𝗽: 0
𝗣𝗮𝘆𝗼𝘂𝘁:  13,442

𝗕𝘂𝗴 𝗦𝘂𝗺𝗺𝗮𝗿𝘆: Empty market updates don't request oracle versions, causing fee and funding calculations to use