# Findings Database — 0xSimao

> 778 published findings from 71 security reviews and public competitions.

- **778** findings listed
- **189** critical and high
- **226** medium severity
- **61** protocols
- **39** reports read

Severity, title and source for every finding this site can show. A row marked as a team report is a firm's review that I worked on, not a finding credited to me alone; a row with no findings says why it has none.

## Morpho Midnight II

Blackthorn · Lending · 2026-07-23

[protocol](https://morpho.org/)

Report not published.

## Tread.fi

Sherlock · Trading infrastructure · 2026-07-20

[protocol](https://www.tread.fi/)

Report not published.

## Fira CDOSquared

Sherlock · Fixed-rate lending · 2026-07-15

[protocol](https://www.fira.money/)

Report not published.

## Morpho Blue Bundles

Blackthorn · Lending · 2026-07-14

[protocol](https://morpho.org/) · [report](https://github.com/0xsimao/audits/blob/main/Blackthorn/2026-07-14-morpho-blue-bundles.pdf)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Info | `BlueBundlesV1::blueBundlesV1RepayAndWithdrawCollateral()` may transfer a null leftover | [read it](https://0xsimao.com/findings/morpho-blue-bundles-repay-collateral-transfer-leftover) |

## Infra Labs USHP

Sherlock · Yield tokenisation · 2026-07-06

Report not published.

## Tenor

Sherlock · Fixed-rate lending · 2026-07-05

[protocol](https://www.tenor.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2026-07-05-tenor.pdf)

No findings.

## Redacted

0xSimao · 2026-07-01

Report not published.

## Redacted

0xSimao · 2026-07-01

Report not published.

## Morpho II

Sherlock · Lending · 2026-06-11

[protocol](https://morpho.org/)

Report not published.

## Morpho

Sherlock · Lending · 2026-06-10

[protocol](https://morpho.org/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2026-06-10-morpho.pdf)

No findings.

## ODEI

Sherlock · AI agent infrastructure · 2026-06-05

[report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2026-06-05-odei.pdf)

No findings.

## Redacted

0xSimao · 2026-06-01

Report not published.

## Tenor Markets

Blackthorn · Fixed-rate lending · 2026-05-22

[protocol](https://www.tenor.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Blackthorn/2026-05-22-tenor-markets.pdf)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Low | MidnightSupplyVaultSharesCallback deposits into ERC4626 without a min shares slippage bound | [read it](https://0xsimao.com/findings/tenor-markets-callback-erc4626-slippage-bound) |
| Low | MidnightVaultExecutor::onLiquidate forces liquidators to provide callback data and never refunds leftover loan tokens | [read it](https://0xsimao.com/findings/tenor-markets-liquidate-callback-refunds-leftover) |
| Low | ClampLib::mulDivDownInverse reverts on `target == type(uint256).max` before the overflow guard runs | [read it](https://0xsimao.com/findings/tenor-markets-reverts-overflow-guard-runs) |
| Low | ClampLib::mulDivDownInverse contains a dead `n == 0` check | [read it](https://0xsimao.com/findings/tenor-markets-clamp-inverse-contains-dead) |
| Low | ClampLib::mulDivUpInverse overflows on large `target`, DoSing SELL offer reads | [read it](https://0xsimao.com/findings/tenor-markets-overflows-sell-offer-reads) |

## Babylon II

Sherlock · Bitcoin staking · 2026-05-18

[protocol](https://babylonlabs.io/)

Report not published.

## Babylon

Sherlock · Bitcoin staking · 2026-04-13

[protocol](https://babylonlabs.io/)

Report not published.

## Morpho Midnight

Blackthorn · Lending · 2026-04-06

[protocol](https://morpho.org/) · [report](https://github.com/0xsimao/audits/blob/main/Blackthorn/2026-04-06-morpho-midnight.pdf)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Low | Chain fork changes all obligation Ids, making them unreachable | [read it](https://0xsimao.com/findings/morpho-midnight-fork-obligation-ids-unreachable) |
| Low | Midnight constructor can use `msg.sender` instead of reading `roleSetter` from storage | [read it](https://0xsimao.com/findings/morpho-midnight-midnight-reading-setter-storage) |
| Low | `midnight` parameter in `MidnightBundles` could be set in the constructor | [read it](https://0xsimao.com/findings/morpho-midnight-midnight-parameter-bundles-constructor) |
| Low | `proof.length` can be used instead of`height` in `EcrecoverRatifier.isRatified` | [read it](https://0xsimao.com/findings/morpho-midnight-proof-ecrecover-ratifier-ratified) |
| Info | `testReturnJumps` asserts the wrong ratio direction | [read it](https://0xsimao.com/findings/morpho-midnight-test-jumps-asserts-direction) |

## Synth OS

Sherlock · On-chain robotics · 2026-03-23

[protocol](https://www.synthos.link/)

Report not published.

## Mezzanine II

Sherlock · Corporate finance platform · 2026-03-20

[protocol](https://www.mezzanine.xyz/)

Report not published.

## PixieChess

Sherlock · On-chain chess wagering · 2026-03-16

[protocol](https://www.pixiechess.xyz/)

Report not published.

## Evro Finance

Sherlock · EUR stablecoin · 2026-03-03

Report not published.

## Mezzanine

Sherlock · Corporate finance platform · 2026-02-26

[protocol](https://www.mezzanine.xyz/)

Report not published.

## Usual IV

Sherlock · Stablecoin issuer · 2026-02-16

[protocol](https://usual.money/)

Report not published.

## Drake

Sherlock · Perpetuals DEX · 2026-01-27

[protocol](https://docs.drake.exchange/)

Report not published.

## Opencover

Sherlock · Insurance · 2026-01-19

[contest](https://audits.sherlock.xyz/contests/1222)

No findings.

## Superfluid

Sherlock · Money streaming · 2026-01-13

[protocol](https://superfluid.org/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2026-01-13-superfluid.pdf)

7 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | AaveETHYieldBackend uses wrong WETH address for Polygon (returns WETH instead of WPOL) | [read it](https://0xsimao.com/findings/superfluid-aave-eth-yield-weth) |
| Medium | Aave rounding behavior allows malicious users to drain accumulated yield via small withdrawals | [read it](https://0xsimao.com/findings/superfluid-aave-rounding-drain-yield) |
| Low | AaveYieldBackend.deposit() DoS when Aave pool is paused, frozen, or at supply cap | [read it](https://0xsimao.com/findings/superfluid-aave-yield-deposit-paused) |
| Low | ERC4626YieldBackend does not support vaults with deposit/withdrawal fees or slashing | [read it](https://0xsimao.com/findings/superfluid-erc4626-yield-withdrawal-slashing) |
| Low | ERC4626YieldBackend.withdrawMax() silently succeeds when vault is paused, leaving funds stuck | [read it](https://0xsimao.com/findings/superfluid-erc4626-yield-paused-stuck) |
| Low | ERC4626YieldBackend.withdrawSurplus() uses convertToAssets() which doesn't account for fees | [read it](https://0xsimao.com/findings/superfluid-erc4626-yield-withdraw-fees) |
| Low | SuperToken._skipSelfMint silently skips minting, breaking custom SuperToken implementations | [read it](https://0xsimao.com/findings/superfluid-super-mint-skips-implementations) |

## Aave V4

Sherlock · Lending · 2026-01-12

[contest](https://audits.sherlock.xyz/contests/1209)

No findings.

## Usual V

Sherlock · Stablecoin issuer · 2025-12-29

[protocol](https://usual.money/)

Report not published.

## Evro Finance II

Sherlock · EUR stablecoin · 2025-12-26

Report not published.

## Spectra MetaVault

Sherlock · Yield-tokenisation vaults · 2025-12-16

[protocol](https://www.spectra.finance/)

Report not published.

## Usual III

Sherlock · Stablecoin issuer · 2025-12-02

[protocol](https://usual.money/)

Report not published.

## Spirit Protocol

0xSimao · AI revenue sharing · 2025-11-28

[report](https://github.com/0xsimao/audits/blob/main/0xSimao/2025-11-28-spirit-protocol.pdf)

7 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | SuperTokens are vulnerable to attacker frontrunning and minting free tokens | [read it](https://0xsimao.com/findings/spirit-protocol-super-frontrunning-minting-free) |
| High | Uniswap v4 pool initialization can be frontrunned, setting an arbitrary price, and stealing tokens | [read it](https://0xsimao.com/findings/spirit-protocol-uniswap-initialization-frontrunned-price) |
| High | Wrong rounding direction in StakingPool::unstake() can be abused | [read it](https://0xsimao.com/findings/spirit-protocol-rounding-staking-unstake-abused) |
| Medium | SpiritFactory won't be able to stop the Airstream contract | [read it](https://0xsimao.com/findings/spirit-protocol-spirit-won-stop-airstream) |
| Low | StakingPool is missing rewards distribution end logic | [read it](https://0xsimao.com/findings/spirit-protocol-staking-rewards-distribution-end) |
| Info | SpiritVestingFactory::createSpiritVestingContract overwrites the spiritVestings mapping for the same recipient | [read it](https://0xsimao.com/findings/spirit-protocol-vesting-overwrites-vestings-recipient) |
| Info | SpiritVestingFactory::setTreasury() could be 2 factor, as well as the AccessControl OZ contract used in the codebase | [read it](https://0xsimao.com/findings/spirit-protocol-vesting-well-access-control) |

## BMX

Sherlock · Perpetuals DEX · 2025-11-18

[protocol](https://www.bmx.trade/)

Report not published.

## stNXM by EaseDeFi

Sherlock · Liquid staking for Nexus Mutual · 2025-11-17

[contest](https://audits.sherlock.xyz/contests/1203)

5 findings. The platform has not published this contest's findings.

## Usual II

Sherlock · Stablecoin issuer · 2025-11-11

[protocol](https://usual.money/)

Report not published.

## Maple Finance III

Sherlock · Institutional lending · 2025-10-22

[protocol](https://maple.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-10-22-maple-finance-iii.pdf)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Low | `SyrupBitcoinRouter::setAssetController()` could always allow the asset controller to be set to 0 | [read it](https://0xsimao.com/findings/maple-finance-iii-syrup-bitcoin-asset-controller) |
| Low | Attackers can DoS redemptions by cancelling requests just before the batch is processed | [read it](https://0xsimao.com/findings/maple-finance-iii-redemptions-cancelling-requests-processed) |
| Low | `SortedLinkedList::getAllValues()` could add a paginated function to prevent DoS | [read it](https://0xsimao.com/findings/maple-finance-iii-sorted-linked-list-paginated) |
| Info | `SyrupBitcoinRouter::processRedemptions()` could be optimized by batching transfers together | [read it](https://0xsimao.com/findings/maple-finance-iii-process-batching-transfers-together) |
| Info | `SyrupBitcoinRouter::requestRedeem()` could also check if the asset picked to redeem has liquidity | [read it](https://0xsimao.com/findings/maple-finance-iii-syrup-bitcoin-redeem-picked) |

## Timeswap v3

Sherlock · Oracleless money markets · 2025-09-15

[protocol](https://timeswap.io/)

Report not published.

## Maple Finance II

Sherlock · Institutional lending · 2025-09-08

[protocol](https://maple.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-09-08-maple-finance-ii.pdf)

3 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Low | Delay can not be set to default value once set to a specific per function value | [read it](https://0xsimao.com/findings/maple-finance-ii-delay-default-specific-function) |
| Low | CEI pattern is not followed in `GovernorTimelock::executeProposals()` | [read it](https://0xsimao.com/findings/maple-finance-ii-cei-followed-timelock-proposals) |
| Low | `GovernorTimelock::_call()` assembly revert block doesn't have the memory safe attribute | [read it](https://0xsimao.com/findings/maple-finance-ii-timelock-assembly-revert-attribute) |

## BMX

Sherlock · Perpetuals DEX · 2025-09-02

[contest](https://audits.sherlock.xyz/contests/1154)

10 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | DoSed `Voter::finalize()` due to unbounded pending removals lacking a batch argument variable | [read it](https://0xsimao.com/findings/bmx-voter-unbounded-removals-lacking) |
| High | Finalize-window vote-changing vulnerability: auto-voters can alter choices post-epoch to manipulate results | [read it](https://0xsimao.com/findings/bmx-vote-vulnerability-choices-epoch) |
| High | `RangePool::adjustToTick()` desyncs when `nextTick == tick` leading to stolen fees | [read it](https://0xsimao.com/findings/bmx-adjust-desyncs-stolen-fees) |
| High | Reward Token Loss for LPs During NFT Position Transfer | [read it](https://0xsimao.com/findings/bmx-reward-nft-position-transfer) |
| High | `Voter::finalize()` incorrect rewards distribution due to transfering WETH before calling `distributor::setTokensPerInterval()` | [read it](https://0xsimao.com/findings/bmx-voter-rewards-transfering-weth) |
| Medium | Unconditional lastUpdated advance in RangePool.sync leads to loss of streamed BMX when pool liquidity == 0 | [read it](https://0xsimao.com/findings/bmx-unconditional-range-streamed-bmx) |
| Medium | Integer Truncation in Incentive Rate Permanently Locks Unstreamed Rewards | [read it](https://0xsimao.com/findings/bmx-truncation-permanently-unstreamed-rewards) |
| Medium | Users always pay fee on the full swapped amount in the `DeliHook`, even if the swap is smaller | [read it](https://0xsimao.com/findings/bmx-fee-full-swapped-hook) |
| Medium | `DeliHookConstantProduct` swapping `exactOutput` and `_feeFromOutput` is incorrect | [read it](https://0xsimao.com/findings/bmx-hook-product-output-fee) |
| Medium | Attacker can swap wBTC in the DeliHook multiples times to not pay / pay less swap fees | [read it](https://0xsimao.com/findings/bmx-btc-hook-multiples-fees) |

## Honeypop Staking

Sherlock · Loyalty rewards staking · 2025-09-01

[protocol](https://www.honeypop.io/)

Report not published.

## Morpho Vault V2

Blackthorn · Curated yield vaults · 2025-08-13

[protocol](https://morpho.org/) · [report](https://github.com/0xsimao/audits/blob/main/Blackthorn/2025-08-13-morpho-vault-v2.pdf)

6 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | `VaultV2::withdraw/redeem()` are vulnerable to slippage, so another function could be added to protect users | [read it](https://0xsimao.com/findings/morpho-vault-v2-withdraw-redeem-slippage-protect) |
| Low | Performance and management fee updates may technically still apply to already earned interest | [read it](https://0xsimao.com/findings/morpho-vault-v2-fee-technically-earned-interest) |
| Low | Performance and management fees could round up to protect the protocol | [read it](https://0xsimao.com/findings/morpho-vault-v2-performance-fees-round-protect) |
| Low | Adapters could store the index instead of true in the `VaultV2` to remove the O(n) search | [read it](https://0xsimao.com/findings/morpho-vault-v2-adapters-store-index-search) |
| Low | A `deallocateAll()` function could be useful to successfully guarantee market removal in the Morpho market adapter | [read it](https://0xsimao.com/findings/morpho-vault-v2-deallocate-successfully-guarantee-morpho) |
| Info | `submit()` could be more verbose when a selector has been abdicated | [read it](https://0xsimao.com/findings/morpho-vault-v2-submit-verbose-selector-abdicated) |

## Cap

Sherlock · Stablecoin issuer · 2025-07-10

[contest](https://audits.sherlock.xyz/contests/990)

2 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | `ViewLogic::maxLiquidatable()` doesn't take the bonus into account, making the agent liquidatable again | [read it](https://0xsimao.com/findings/cap-view-liquidatable-bonus-agent) |
| Medium | Cannot repay or liquidate on paused asset | [read it](https://0xsimao.com/findings/cap-cannot-repay-liquidate-paused) |

## Yieldoor III

0xSimao · Leveraged yield farming · 2025-06-23

[protocol](https://app.yieldoor.com/) · [report](https://github.com/0xsimao/audits/blob/main/0xSimao/2025-06-23-yieldoor-iii.pdf)

7 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Low | Missing nonReentrant functionality in some execution paths | [read it](https://0xsimao.com/findings/yieldoor-iii-reentrant-functionality-execution-paths) |
| Low | It's possible for debt to be stuck in the LoopedVault when rebalancing from Aave to Morpho | [read it](https://0xsimao.com/findings/yieldoor-iii-debt-stuck-aave-morpho) |
| Low | CEI pattern is not followed on LoopedVault::fulfillWithdraw() | [read it](https://0xsimao.com/findings/yieldoor-iii-cei-followed-fulfill-withdraw) |
| Low | Slippage protection could be added to LoopedVault::requestWithdraw() in case of black swan event | [read it](https://0xsimao.com/findings/yieldoor-iii-slippage-withdraw-black-swan) |
| Low | Missing key events when requesting withdrawals that could be important for the allocator bot | [read it](https://0xsimao.com/findings/yieldoor-iii-requesting-withdrawals-allocator-bot) |
| Low | LoopedVault::maxMint() and LoopedVault::maxRedeem() are not overriden | [read it](https://0xsimao.com/findings/yieldoor-iii-looped-mint-redeem-overriden) |
| Low | User may be requesting/fulfilling withdrawals at better rates than the real share/asset ratio | [read it](https://0xsimao.com/findings/yieldoor-iii-requesting-fulfilling-withdrawals-share) |

## Yieldoor II

0xSimao · Leveraged yield farming · 2025-06-20

[protocol](https://app.yieldoor.com/) · [report](https://github.com/0xsimao/audits/blob/main/0xSimao/2025-06-20-yieldoor-ii.pdf)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Vesting interest is not reset to 0 in case there is no interest in LoopedVault11::updateTotalAssets() | [read it](https://0xsimao.com/findings/yieldoor-ii-vesting-interest-reset-vault11) |
| Medium | Code has typos in RebalanceLogic::repayAavePosition() leading to undefined behaviour | [read it](https://0xsimao.com/findings/yieldoor-ii-repay-aave-undefined-behaviour) |
| Low | RebalanceLogic::rebalanceCallback() doesn't update lastTotalAssets when rebalancing from morpho to morpho | [read it](https://0xsimao.com/findings/yieldoor-ii-rebalance-callback-rebalancing-morpho) |
| Low | Inconsistent updateTotalAssets modifier usage | [read it](https://0xsimao.com/findings/yieldoor-ii-inconsistent-assets-modifier-usage) |
| Info | Duplicated approval in RebalanceLogic::rebalanceCallback() | [read it](https://0xsimao.com/findings/yieldoor-ii-duplicated-approval-rebalance-callback) |

## Symbiotic Relay

Sherlock · Staking · 2025-06-19

[contest](https://audits.sherlock.xyz/contests/967)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Most KeyRegistry, VotingPowerProvider functions can be DoSed | [read it](https://0xsimao.com/findings/symbiotic-relay-registry-voting-power-provider) |
| Medium | Changing the epoch duration will completely break the vault and the slashers | [read it](https://0xsimao.com/findings/symbiotic-relay-epoch-duration-completely-slashers) |
| Medium | BlsBn254 is not available in certain chains due to hardcoded gas limit | [read it](https://0xsimao.com/findings/symbiotic-relay-bls-bn254-hardcoded-gas) |
| Medium | A malicious operator will control consensus without risking stake (stake-exit lag exploit) | [read it](https://0xsimao.com/findings/symbiotic-relay-control-consensus-risking-stake) |
| Medium | Malicious operator can alone, with any voting power smaller than quorum forge a proof | [read it](https://0xsimao.com/findings/symbiotic-relay-alone-voting-quorum-proof) |

## Arrakis

Sherlock · Market making · 2025-06-17

[protocol](https://arrakis.finance/)

Report not published.

## Chronicle

Sherlock · Oracles · 2025-06-09

[protocol](https://chroniclelabs.org/)

Report not published.

## Maple Finance I

Sherlock · Institutional lending · 2025-06-08

[protocol](https://maple.finance/)

Report not published.

## Superfluid Locker System II

Sherlock · Streaming · 2025-06-04

[contest](https://audits.sherlock.xyz/contests/968) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/contests/2025-06-04-superfluid-locker-system-ii.md)

6 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Staked tokens inside FluidLocker can be withdrawn without calling Unstake | [read it](https://0xsimao.com/findings/superfluid-locker-system-ii-staked-inside-withdrawn-unstake) |
| High | Pumponomics can be skipped when using FluidLocker::provideLiquidity | [read it](https://0xsimao.com/findings/superfluid-locker-system-ii-pumponomics-skipped-fluid-provide) |
| Medium | Incorrect initial deposit calculation may cause cancelProgram to revert | [read it](https://0xsimao.com/findings/superfluid-locker-system-ii-initial-deposit-program-revert) |
| Medium | Fluid (SUP) can be withdrawn from the Locker while the unlock flag is false | [read it](https://0xsimao.com/findings/superfluid-locker-system-ii-sup-withdrawn-flag-false) |
| Medium | Program start failure due to incorrect buffer calculation | [read it](https://0xsimao.com/findings/superfluid-locker-system-ii-program-start-failure-buffer) |
| Medium | Locker owners can leverage low liquidity pools to bypass the tax mechanism | [read it](https://0xsimao.com/findings/superfluid-locker-system-ii-owners-low-bypass-mechanism) |

## Usual I

Sherlock · Stablecoin issuer · 2025-06-03

[protocol](https://usual.money/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-06-03-usual-i.pdf)

No findings.

## Beraborrow II

Sherlock · CDP stablecoin · 2025-06-03

[protocol](https://www.beraborrow.com/)

Report not published.

## Pond GNN

Sherlock · Crypto AI models · 2025-05-22

[protocol](https://cryptopond.xyz/)

Report not published.

## Extrafi XLend

Sherlock · Lending · 2025-05-21

[contest](https://audits.sherlock.xyz/contests/826)

No findings.

## Yieldoor I

0xSimao · Leveraged yield farming · 2025-05-12

[protocol](https://app.yieldoor.com/) · [report](https://github.com/0xsimao/audits/blob/main/0xSimao/2025-05-12-yieldoor-i.pdf)

8 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Fees or vested position withdrawal in ShadowStrategyGauge::addVestingPosition() when collecting fees will be revested | [read it](https://0xsimao.com/findings/yieldoor-i-fees-withdrawal-vesting-revested) |
| Low | DoS risk in IRamsesGauge(gauge).getReward() when enough periods have passed | [read it](https://0xsimao.com/findings/yieldoor-i-risk-ramses-reward-periods) |
| Low | Newly added rewards will not be immediately collected | [read it](https://0xsimao.com/findings/yieldoor-i-newly-rewards-immediately-collected) |
| Low | ShadowStrategyGauge::addVestingPosition() may revert if there is 0 liquidity to add | [read it](https://0xsimao.com/findings/yieldoor-i-shadow-gauge-vesting-revert) |
| Low | If any of the reward tokens doesn't have a liquid pool, it may be impossible to collect rewards | [read it](https://0xsimao.com/findings/yieldoor-i-reward-liquid-impossible-rewards) |
| Low | Swap amount can be 0 as it divides the balance by 2, DoSing ShadowStrategyGauge::collectGaugeRewards() | [read it](https://0xsimao.com/findings/yieldoor-i-divides-sing-shadow-rewards) |
| Info | If enough rebalances are performed, ShadowStrategyGauge::collectGaugeRewards() could be DoSed | [read it](https://0xsimao.com/findings/yieldoor-i-rebalances-performed-shadow-rewards) |
| Info | If xShadow is token0 or token1, ShadowStrategyGauge::collectGaugeRewards() will take protocol fee on user funds | [read it](https://0xsimao.com/findings/yieldoor-i-token0-token1-rewards-fee) |

## Kyo Finance

Sherlock · DEX and vote-escrow · 2025-05-09

[protocol](https://app.kyo.finance/)

Report not published.

## Beraborrow I

Sherlock · CDP stablecoin · 2025-04-25

[protocol](https://www.beraborrow.com/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-04-25-beraborrow-i.pdf)

19 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Lost withdrawals due to `ManagedLeveragedVault::openDen()` using all `asset()` balance | [read it](https://0xsimao.com/findings/beraborrow-i-lost-withdrawals-managed-den) |
| Medium | `ManagedLeveragedVault.sol::deposit()` is missing slippage control | [read it](https://0xsimao.com/findings/beraborrow-i-sol-deposit-slippage-control) |
| Medium | DoSed withdrawals due to `ManagedLeveragedVault::executeWithdrawalEpoch()` repaying debt above limit | [read it](https://0xsimao.com/findings/beraborrow-i-withdrawals-withdrawal-epoch-debt) |
| Medium | `ManagedLeveragedVault::executeWithdrawalEpoch()` will never work because `cd.prevICR` is not set | [read it](https://0xsimao.com/findings/beraborrow-i-withdrawal-epoch-prev-icr) |
| Medium | `ManagedLeveragedVault::increaseLeverage()` fails when the debt is closed to the limit | [read it](https://0xsimao.com/findings/beraborrow-i-leverage-fails-debt-closed) |
| Medium | `ManagedLeveragedVault::decreaseLeverage()` will not work when it goes below the minimum debt | [read it](https://0xsimao.com/findings/beraborrow-i-decrease-goes-below-debt) |
| Medium | Protocol will need to donate minimum debt for all new ManagedLeveragedVaults | [read it](https://0xsimao.com/findings/beraborrow-i-need-donate-debt-vaults) |
| Medium | Missing several `safeERC20` functions | [read it](https://0xsimao.com/findings/beraborrow-i-several-safe-erc20-functions) |
| Medium | `ManagedLeveragedVault::executeWithdrawalEpoch()` incorrect ICR and DoSed withdrawals due to not accouting for fees | [read it](https://0xsimao.com/findings/beraborrow-i-withdrawal-epoch-withdrawals-fees) |
| Low | Unused/useless code | [read it](https://0xsimao.com/findings/beraborrow-i-unused-useless-code) |
| Low | Hints on withdrawal may fail as the ICR changes between claiming collateral surplus and repaying debt | [read it](https://0xsimao.com/findings/beraborrow-i-hints-withdrawal-collateral-debt) |
| Low | `ManagedLeveragedVault::deposit()` slippage control on `collVaultShares` is not intuitive | [read it](https://0xsimao.com/findings/beraborrow-i-deposit-slippage-control-shares) |
| Low | Incorrect `ERC4626ExceededMaxRedeem` event on `ManagedLeveragedVault.sol:: cancelWithdrawalIntent()` | [read it](https://0xsimao.com/findings/beraborrow-i-erc4626-exceeded-redeem-withdrawal) |
| Low | `ManagedLeveragedVault::increaseLeverage()` will never work in Recovery mode | [read it](https://0xsimao.com/findings/beraborrow-i-leverage-work-recovery-mode) |
| Low | `ManagedLeveragedVault::getAvailableDebt()` used in `ManagedLeveragedVault::increaseLeverage()` is incorrect | [read it](https://0xsimao.com/findings/beraborrow-i-available-debt-increase-leverage) |
| Low | `ManagedLeveragedVault::donateCollateral()` is missing a slippage check | [read it](https://0xsimao.com/findings/beraborrow-i-managed-donate-collateral-slippage) |
| Low | Some view functions will not work under certain conditions | [read it](https://0xsimao.com/findings/beraborrow-i-view-work-certain-conditions) |
| Low | `ManagedLeveragedVault::getDebtToUnwindAndCollRequested()` is inaccurate when there are surplus tokens | [read it](https://0xsimao.com/findings/beraborrow-i-debt-unwind-requested-inaccurate) |
| Low | Most `ManagedLeveragedVault` functions are DoSed due to bad debt check | [read it](https://0xsimao.com/findings/beraborrow-i-managed-functions-bad-debt) |

## Aegis

Sherlock · Bitcoin-backed stablecoin · 2025-04-22

[protocol](https://www.aegisweb3.com/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-04-22-aegis.pdf)

3 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Attacker can DoS user withdrawals at no cost | [read it](https://0xsimao.com/findings/aegis-attacker-user-withdrawals-cost) |
| Low | Missing `maxRedeem()` implementation | [read it](https://0xsimao.com/findings/aegis-missing-max-redeem-implementation) |
| Low | Donation attack possible, although unlikely, could make an initial deposit | [read it](https://0xsimao.com/findings/aegis-donation-although-unlikely-deposit) |

## Zetachain

Sherlock · L1 · 2025-04-14

[contest](https://audits.sherlock.xyz/contests/857)

8 findings. The platform has not published this contest's findings.

## 1inch

Sherlock · DEX aggregator · 2025-04-14

[protocol](https://1inch.com/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-04-14-1inch.pdf)

3 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Low | Taker fee is underestimated due to incorrect fee calculation | [read it](https://0xsimao.com/findings/1inch-taker-fee-underestimated-calculation) |
| Low | `uniTransfer()` limits the gas limit to 5k in outdated 1inch solidity-utils lib | [read it](https://0xsimao.com/findings/1inch-uni-transfer-gas-1inch) |
| Low | Significant rounding error in whitelist discount that could be avoided | [read it](https://0xsimao.com/findings/1inch-rounding-whitelist-discount-avoided) |

## Staking Part 2

CodeHawks · Starknet L2 staking · 2025-04-03

[contest](https://codehawks.cyfrin.io/contests/cm8iwzzel0002jv03235nowd6)

No findings.

## Gaib

Sherlock · AI compute financing · 2025-03-28

[protocol](https://gaib.ai/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-03-28-gaib.pdf)

7 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | User fund loss due to depositing before `unearn()` | [read it](https://0xsimao.com/findings/gaib-fund-loss-depositing-unearn) |
| Medium | `PreDepositVault` will not work for USDT | [read it](https://0xsimao.com/findings/gaib-pre-deposit-work-usdt) |
| Medium | `PreDepositVault` does not collect interest for `WBTC` | [read it](https://0xsimao.com/findings/gaib-pre-deposit-interest-wbtc) |
| Low | `PreDepositVault::maxDeposit/Mint()` are missing `maxDepositLimit` as per the ERC4626 spec | [read it](https://0xsimao.com/findings/gaib-deposit-mint-erc4626-spec) |
| Low | ATokens can be swept of the `PreDepositVault` | [read it](https://0xsimao.com/findings/gaib-tokens-swept-pre-deposit) |
| Low | Rounding error in Aave Lending Pool | [read it](https://0xsimao.com/findings/gaib-rounding-error-aave-lending) |
| Low | `PreDepositVault::sweep()` uses `address.transfer` which does not work for certain wallets | [read it](https://0xsimao.com/findings/gaib-deposit-sweep-transfer-wallets) |

## StarkWare Perps

Code4rena · Perpetuals DEX · 2025-03-17

[contest](https://code4rena.com/audits/2025-03-starkware-perps)

No findings.

## Felix

0xSimao · CDP stablecoin · 2025-03-14

[protocol](https://www.usefelix.xyz/) · [report](https://github.com/0xsimao/audits/blob/main/0xSimao/2025-03-14-felix.pdf)

7 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Attacker can trigger temporary shutdown due to RedStonePriceFeedBase missing gas check | [read it](https://0xsimao.com/findings/felix-temporary-shutdown-price-gas) |
| Info | Missing provideToSpOnBehalfOf interface | [read it](https://0xsimao.com/findings/felix-missing-provide-behalf-interface) |
| Info | In case of success, some leftover funds could still be present in the adapter | [read it](https://0xsimao.com/findings/felix-success-leftover-present-adapter) |
| Info | Missing priceFeedDisabled event in RedStonePriceFeedBase | [read it](https://0xsimao.com/findings/felix-price-disabled-red-stone) |
| Info | Gas forwarded by the CurveGaugeDistributor could be limited to further prevent OOG | [read it](https://0xsimao.com/findings/felix-gas-forwarded-curve-limited) |
| Info | The check rewardSelector != ZERO BYTES4 && rewardDestination.isContract() could be improved | [read it](https://0xsimao.com/findings/felix-reward-zero-bytes4-improved) |
| Info | InterestRouterV2::triggerDistribution() may be vulnerable to arbitrage stratregies due to being permissionless | [read it](https://0xsimao.com/findings/felix-interest-distribution-stratregies-permissionless) |

## Crestal Network

Sherlock · AI agent · 2025-03-11

[contest](https://audits.sherlock.xyz/contests/755)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Anyone who is approving `BlueprintV5` contract to spend ERC20 can get drained because `Payment::payWithERC20` | [read it](https://0xsimao.com/findings/crestal-network-approving-blueprint-spend-erc20) |
| Medium | `createCommonProjectIDAndDeploymentRequest()` hardcodes request id index to 0, leading to lost requests for users | [read it](https://0xsimao.com/findings/crestal-network-common-project-hardcodes-index) |
| Medium | Signatures missing some parameters being vulnerable to attackers using them coupled with malicious parameters | [read it](https://0xsimao.com/findings/crestal-network-signatures-parameters-them-coupled) |
| Medium | Signature Replay attack possible on `updateWorkerDeploymentConfigWithSig()` in Blueprintcore.sol which leads to users lose the funds | [read it](https://0xsimao.com/findings/crestal-network-signature-replay-blueprintcore-lose) |
| Medium | Worker-Induced Denial-of-Service in Deployment Requests Due to Lack of a Cancellation Mechanism | [read it](https://0xsimao.com/findings/crestal-network-worker-induced-denial-cancellation) |

## Symmio, Staking and Vesting

Sherlock · Staking · 2025-03-07

[contest](https://audits.sherlock.xyz/contests/838)

2 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Bad check in `Vesting.sol::_resetVestingPlans` will prevent users from adding additional liquidity in `SymmVesting.sol` | [read it](https://0xsimao.com/findings/symmio-staking-and-vesting-vesting-plans-additional-symm) |
| Medium | Double spending attack in the Vesting contract | [read it](https://0xsimao.com/findings/symmio-staking-and-vesting-double-spending-attack-vesting) |

## Yieldoor

Sherlock · CLMM · 2025-02-24

[contest](https://audits.sherlock.xyz/contests/791) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/contests/2025-02-24-yieldoor.md)

12 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Strategy main ticks are set according to the tick in slot0, leading to incorrect allocation and loss of funds | [read it](https://0xsimao.com/findings/yieldoor-main-according-slot0-allocation) |
| High | Base calculation in `Leverager::isLiquidateable()` is incorrect as the max leverage may be smaller | [read it](https://0xsimao.com/findings/yieldoor-leverager-liquidateable-leverage-smaller) |
| High | Contradiction between high-leverage and liquidation check of position | [read it](https://0xsimao.com/findings/yieldoor-contradiction-high-leverage-liquidation) |
| Medium | `Vault::_calcDeposit()` will overflow for low priced tokens | [read it](https://0xsimao.com/findings/yieldoor-calc-deposit-overflow-priced) |
| Medium | `Leverager::deposit`, does not support multi-hop swaps with `exactOutput` | [read it](https://0xsimao.com/findings/yieldoor-deposit-hop-exact-output) |
| Medium | `ReserveLogic::_updateIndexes()` assumes the utilization rate was constant the whole time when calculating the new borrows | [read it](https://0xsimao.com/findings/yieldoor-constant-whole-calculating-borrows) |
| Medium | Strategy main ticks are not symmetric when the tick spacing is one due to incorrect isLowerSided inequality | [read it](https://0xsimao.com/findings/yieldoor-symmetric-spacing-sided-inequality) |
| Medium | `Strategy::checkPoolActivity()` incorrect check leads to vulnerable price | [read it](https://0xsimao.com/findings/yieldoor-activity-incorrect-vulnerable-price) |
| Medium | `Strategy::checkPoolActivity()` does not look as far back as it should | [read it](https://0xsimao.com/findings/yieldoor-activity-look-far-back) |
| Medium | Incorrect modulo calculation in secondary position ticks leads to active position and division by zero | [read it](https://0xsimao.com/findings/yieldoor-modulo-secondary-division-zero) |
| Medium | `Vault::withdraw()` withdraws too much liquidity leading to idle capital and loss of fees | [read it](https://0xsimao.com/findings/yieldoor-withdraw-withdraws-capital-fees) |
| Medium | Locked funds due to underflow in withdrawal | [read it](https://0xsimao.com/findings/yieldoor-locked-funds-underflow-withdrawal) |

## Nerite

Sherlock · CDP stablecoin · 2025-02-03

[protocol](https://www.nerite.org/) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/private-audits/2025-02-03-nerite.pdf)

3 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | `BoldToken` initialization can be frontrun to silently mint/approve bold to an attacker | [read it](https://0xsimao.com/findings/nerite-initialization-frontrun-mint-approve) |
| Low | New debt from adjusted trove is double counted towards the limit | [read it](https://0xsimao.com/findings/nerite-debt-adjusted-counted-towards) |
| Low | Pausable or Blacklist tokens may cause liquidations to fail | [read it](https://0xsimao.com/findings/nerite-pausable-blacklist-liquidations-fail) |

## Beraborrow

Sherlock · Lending · 2025-01-13

[contest](https://audits.sherlock.xyz/contests/741)

No findings.

## Pengu Airdrop

Three Sigma · Airdrop claims · 2024-12-09

Report not published.

## Autonomint

Sherlock · Hedged stablecoin · 2024-12-04

[contest](https://audits.sherlock.xyz/contests/569) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/contests/2024-12-04-autonomint.md)

38 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Borrower withdrawing at a loss will cause losses for cds depositors that only withdraw after the price recovers | [read it](https://0xsimao.com/findings/autonomint-losses-withdraw-price-recovers) |
| High | Total cds deposited amount is incorrectly modified when cds depositor is at a loss, leading to stuck USDa | [read it](https://0xsimao.com/findings/autonomint-deposited-modified-depositor-stuck) |
| High | Cds depositors profit up to the strike price is not redeemable as the total cds deposited amount is not increased | [read it](https://0xsimao.com/findings/autonomint-strike-price-redeemable-increased) |
| High | Cds depositor profit is never taxed as the tax is only applied on the option fees | [read it](https://0xsimao.com/findings/autonomint-depositor-taxed-applied-fees) |
| High | Type 1 borrower liquidation will incorrectly add cds profit directly to `totalCdsDepositedAmount` | [read it](https://0xsimao.com/findings/autonomint-type-liquidation-directly-deposited) |
| High | Liquidation profit is never given to cds depositors who will take these losses | [read it](https://0xsimao.com/findings/autonomint-liquidation-profit-depositors-losses) |
| High | `borrowing::withdraw()` at a loss will increase downside protected and misscalculate option fees | [read it](https://0xsimao.com/findings/autonomint-withdraw-downside-misscalculate-fees) |
| High | Some liquidated collateral will be locked | [read it](https://0xsimao.com/findings/autonomint-liquidated-collateral-locked) |
| High | Cds amounts to reduce from each chain are incorrect and will lead to the inability to withdraw cds in one of the chains | [read it](https://0xsimao.com/findings/autonomint-reduce-each-inability-withdraw) |
| High | Potential Underflow in `withdrawInterest` | [read it](https://0xsimao.com/findings/autonomint-underflow-withdraw-interest) |
| High | `borrowing::liquidate()` sends the wrong liquidation index to the destination chain, overwritting liquidation information and getting collateral stuck | [read it](https://0xsimao.com/findings/autonomint-liquidate-liquidation-index-stuck) |
| High | Malicious user can call `borrowing::calculateCumulativeRate()` any number of times to inflate debt rate as `lastEventTime` is not updated | [read it](https://0xsimao.com/findings/autonomint-calculate-times-inflate-debt) |
| High | Late abond holders steal USDa amount from liquidations from earlier abond holders | [read it](https://0xsimao.com/findings/autonomint-abond-steal-liquidations-earlier) |
| High | `CDSLib::withdrawUserWhoNotOptedForLiq()` tax is not stored in the treasury | [read it](https://0xsimao.com/findings/autonomint-withdraw-opted-liq-stored) |
| High | Using LayerZero for synchronizing global states between two chains may lead to overwriting of global states. | [read it](https://0xsimao.com/findings/autonomint-zero-synchronizing-states-overwriting) |
| High | Borrower deposit, withdraw, deposit will reinit `omniChainData.cdsPoolValue`, getting profit stuck for cds depositors | [read it](https://0xsimao.com/findings/autonomint-deposit-withdraw-reinit-stuck) |
| High | Missing Update to `omnichain.totalAvailableLiquidationAmount` in `withdrawUser` | [read it](https://0xsimao.com/findings/autonomint-omnichain-available-liquidation-withdraw) |
| High | Liquidation will reduce total cds deposited amount, leading to incorrect option fees | [read it](https://0xsimao.com/findings/autonomint-liquidation-reduce-option-fees) |
| High | `Borrowing::redeemYields` debits `ABOND` from `msg.sender` but redeems to `user` using `ABOND.State` data from `user` | [read it](https://0xsimao.com/findings/autonomint-redeem-yields-debits-redeems) |
| High | The user overpays the USDA amount for downside protection while withdrawing | [read it](https://0xsimao.com/findings/autonomint-overpays-usda-downside-protection) |
| High | `totalCdsDepositedAmountWithOptionFees` is incorrectly reduced in `CDSLib::withdrawUser()`, leading to stuck option fees | [read it](https://0xsimao.com/findings/autonomint-fees-reduced-withdraw-stuck) |
| High | Strike Price Not Validated Against Strike Percent, Leading to Exploitation Risk | [read it](https://0xsimao.com/findings/autonomint-strike-price-percent-exploitation) |
| High | `treasury.updateYieldsFromLiquidatedLrts()` updates the yield in the current chain, but collateral may be in the other chain | [read it](https://0xsimao.com/findings/autonomint-yields-lrts-yield-collateral) |
| High | odosAssembledData can be manipulated | [read it](https://0xsimao.com/findings/autonomint-odos-assembled-data-manipulated) |
| High | cds owners can withdraw more than expected via manipulating excessProfitCumulativeValue | [read it](https://0xsimao.com/findings/autonomint-owners-withdraw-manipulating-excess) |
| High | Malicious users can DOS the protocol by setting downsideProtected to a large value | [read it](https://0xsimao.com/findings/autonomint-dos-downside-protected-large) |
| Medium | Accumulated profit/losses by the cumulative value is not dealt with in `borrowingLiquidation::liquidationType1()`, leading to losses | [read it](https://0xsimao.com/findings/autonomint-accumulated-dealt-liquidation-type1) |
| Medium | Interest generated by last bond will not go to anyone when liquidating as there is no bond amount to collect it | [read it](https://0xsimao.com/findings/autonomint-interest-generated-bond-liquidating) |
| Medium | `GlobalVariables::oftOrCollateralReceiveFromOtherChains()` calculates the fee as if it was the same in both chains, which is false | [read it](https://0xsimao.com/findings/autonomint-collateral-calculates-fee-both) |
| Medium | `GlobalVariables::oftOrCollateralReceiveFromOtherChains()` always charges twice the collateral on `COLLATERAL_TRANSFER`, which is not needed | [read it](https://0xsimao.com/findings/autonomint-collateral-charges-transfer-needed) |
| Medium | Yield form LRTs are forever stuck in the protocol and cannot be withdrawn | [read it](https://0xsimao.com/findings/autonomint-yield-form-stuck-withdrawn) |
| Medium | DOS on liquidation type 1 due to underflow in cds profits computation | [read it](https://0xsimao.com/findings/autonomint-dos-liquidation-underflow-computation) |
| Medium | Protected downside is not updated when `cds.getTotalCdsDepositedAmount() < downsideProtected` | [read it](https://0xsimao.com/findings/autonomint-protected-downside-updated-deposited) |
| Medium | `Treasury.noOfBorrowers` can be set to 0 by looping wei deposit<->withdrawals and DoS withdrawals and reset borrower debt | [read it](https://0xsimao.com/findings/autonomint-wei-deposit-withdrawals-debt) |
| Medium | `CDSLib::calculateCumulativeRate()` incorrectly only increment the local option fees when there are cds deposits | [read it](https://0xsimao.com/findings/autonomint-increment-local-fees-deposits) |
| Medium | Inconsistent Use of `lastCumulativeRate` in `depositTokens()` and `withdraw()` Functions in `Borrowings` Contract | [read it](https://0xsimao.com/findings/autonomint-cumulative-deposit-withdraw-borrowings) |
| Medium | Withdrawing ionic during liquidation has a flaw | [read it](https://0xsimao.com/findings/autonomint-withdrawing-ionic-liquidation-flaw) |
| Medium | An attacker can manipulate `omniChainData.cdsPoolValue` by breaking protocol. | [read it](https://0xsimao.com/findings/autonomint-manipulate-omni-data-breaking) |

## More Markets

Three Sigma · Lending · 2024-12-02

[protocol](https://www.more.markets/)

Report not published.

## Maple Finance IV

Three Sigma · Institutional lending · 2024-11-26

[protocol](https://maple.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-11-26-maple-finance-iv.pdf)

15 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| Medium | Aave and SavingsUsds strategies may revert when trying to withdraw all funds | [read it](https://0xsimao.com/findings/maple-finance-iv-aave-revert-trying-withdraw) |
| Low | MapleSkyStrategy:: _gemForUsds() suffers a rounding error up to approximately 1e12 Usds | [read it](https://0xsimao.com/findings/maple-finance-iv-suffers-rounding-approximately-1e12) |
| Info | MapleSkyStrategy does not always cache the psm and misses underscores | [read it](https://0xsimao.com/findings/maple-finance-iv-sky-cache-misses-underscores) |
| Info | Differences in the strategy implementations that could be fixed | [read it](https://0xsimao.com/findings/maple-finance-iv-differences-strategy-implementations-fixed) |
| Info | ERC4626::previewRedeem() may revert, which will DoS MaplePool withdrawals | [read it](https://0xsimao.com/findings/maple-finance-iv-erc4626-redeem-revert-withdrawals) |
| Info | The basic strategy does not have slippage control when withdrawing which may lead to arbitrage | [read it](https://0xsimao.com/findings/maple-finance-iv-slippage-control-withdrawing-arbitrage) |
| Info | MapleSkyStrategy::assetsUnderManagement() uses maxWithdraw(), which may return 0 | [read it](https://0xsimao.com/findings/maple-finance-iv-sky-management-withdraw-return) |
| Info | MapleSkyStrategy:: setPsm() should set the old Psm's approval to 0 | [read it](https://0xsimao.com/findings/maple-finance-iv-sky-psm-old-approval) |
| Info | tin in the Psm will cause an instant drop in the share price which could be leveraged by Maple Pool users | [read it](https://0xsimao.com/findings/maple-finance-iv-instant-drop-share-price) |
| Info | There may not be enough gem(Usdc) in the Psm contract, DoSing withdrawals in the Sky Strategy | [read it](https://0xsimao.com/findings/maple-finance-iv-gem-usdc-sing-withdrawals) |
| Info | Usdc to Usds calculation in the Sky Strategy is slightly different than the Psm Usds Wrapper | [read it](https://0xsimao.com/findings/maple-finance-iv-usdc-usds-slightly-wrapper) |
| Info | The DaiJoin contract may be caged which will DoS withdrawals forever | [read it](https://0xsimao.com/findings/maple-finance-iv-dai-join-caged-withdrawals) |
| Info | Withdrawals in the Maple Pool and Sky Strategy may be DoSed in case the DssLitePsm halts buying | [read it](https://0xsimao.com/findings/maple-finance-iv-withdrawals-dss-lite-halts) |
| Info | Aave RewardsController can add Usdc to the rewards list and the strategy has no way to collect the rewards | [read it](https://0xsimao.com/findings/maple-finance-iv-aave-rewards-usdc-way) |
| Info | Inactive or Impaired pool creates arbitrage oportunities | [read it](https://0xsimao.com/findings/maple-finance-iv-inactive-impaired-creates-oportunities) |

## Superfluid Locker System

Sherlock · Streaming · 2024-11-20

[contest](https://audits.sherlock.xyz/contests/648) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/contests/2024-11-20-superfluid-locker-system.md)

6 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | `FluidLocker::_getUnlockingPercentage()` incorrectly divides one of the components of the formula by `S`, leading to always having `80%` penalty | [read it](https://0xsimao.com/findings/superfluid-locker-system-unlocking-components-formula-penalty) |
| High | `FluidLocker::_getUnlockingPercentage()` uses 540 instead of `540 days` leading to stuck funds as the unlocking percentage will be bigger than `100%` and underflow | [read it](https://0xsimao.com/findings/superfluid-locker-system-540-stuck-bigger-underflow) |
| High | `Fontaine` never stops the flows to the tax and recipient, so the buffer component of the flows will be lost | [read it](https://0xsimao.com/findings/superfluid-locker-system-fontaine-stops-flows-component) |
| Medium | An attacker may DoS user Fluid balance increases by frontrunning `FluidLocker::claim()` calls and calling `EP_PROGRAM_MANAGER::batchUpdateUserUnits()` directly | [read it](https://0xsimao.com/findings/superfluid-locker-system-increases-frontrunning-program-directly) |
| Medium | `FluidLocker::_getUnlockingPercentage()` divides before multiplying, suffering a significant precision error | [read it](https://0xsimao.com/findings/superfluid-locker-system-unlocking-multiplying-suffering-precision) |
| Medium | A malicious user may unlock instantly all the funds from the `FluidLocker` when no one is staking in the Tax pool | [read it](https://0xsimao.com/findings/superfluid-locker-system-unlock-instantly-staking-tax) |

## Chiliz Chain System Contracts

Sherlock · L1 · 2024-11-15

[contest](https://audits.sherlock.xyz/contests/550)

No findings.

## Ojo Network

Three Sigma · Oracles · 2024-11-11

[protocol](https://www.ojo.network/)

Report not published.

## Telcoin Update #2

Sherlock · DeFi · 2024-11-06

[contest](https://audits.sherlock.xyz/contests/643)

No findings.

## Zoo.fun

Three Sigma · Token launchpad · 2024-10-25

Report not published.

## Mento

Sherlock · Stablecoin · 2024-10-24

[contest](https://audits.sherlock.xyz/contests/598) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/contests/2024-10-24-mento.md)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | User to sell the last supply will make the exchange contribution forever stuck | [read it](https://0xsimao.com/findings/mento-sell-supply-contribution-stuck) |
| Medium | `GoodDollarExchangeProvider::mintFromExpansion()` will change the price due to a rounding error in the new ratio | [read it](https://0xsimao.com/findings/mento-provider-mint-price-rounding) |
| Medium | Malicious user may frontrun `GoodDollarExpansionController::mintUBIFromReserveBalance()` to make protocol funds stuck | [read it](https://0xsimao.com/findings/mento-frontrun-mint-ubi-stuck) |
| Medium | `TradingLimits::update()` incorrectly only rounds up when `deltaFlowUnits` becomes 0, which will silently increase trading limits | [read it](https://0xsimao.com/findings/mento-limits-delta-flow-becomes) |
| Medium | _getReserveRatioScalar() will give a lesser value than expected | [read it](https://0xsimao.com/findings/mento-ratio-scalar-lesser-expected) |

## Codeup

Three Sigma · DeFi game · 2024-10-23

[report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-10-23-codeup.pdf)

12 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | Total `ETH`, `WETH` and `gameETH` are not tracked which will lead to insolvency | [read it](https://0xsimao.com/findings/codeup-eth-weth-tracked-insolvency) |
| High | Significant rounding errors due to `gameETH` not having precision | [read it](https://0xsimao.com/findings/codeup-rounding-game-eth-precision) |
| High | `tower.gameETHForWithdraw` should be reduced pro-rata when there is not enough `ETH` | [read it](https://0xsimao.com/findings/codeup-tower-eth-withdraw-rata) |
| High | `Codeup::claimCodeupERC20()` may be forever DoSed by creating the `Uniswap` pool before it is called | [read it](https://0xsimao.com/findings/codeup-erc20-forever-creating-uniswap) |
| Medium | `Codeup::claimCodeupERC20()` may revert whenever the `weth` balance is very low | [read it](https://0xsimao.com/findings/codeup-erc20-revert-weth-low) |
| Low | Missing key zero value check | [read it](https://0xsimao.com/findings/codeup-missing-key-zero-value) |
| Low | `Codeup::claimCodeupERC20()` is vulnerable to sandwich attacks | [read it](https://0xsimao.com/findings/codeup-codeup-erc20-sandwich-attacks) |
| Info | Typos in the codebase | [read it](https://0xsimao.com/findings/codeup-typos-codebase) |
| Info | Hardcoded values present in the codebase | [read it](https://0xsimao.com/findings/codeup-hardcoded-values-present-codebase) |
| Info | All functions could have a `started` modifier as they should not be called before the start time | [read it](https://0xsimao.com/findings/codeup-started-modifier-called-time) |
| Info | `Ownable` is unused in `CodeupERC20` and could be removed | [read it](https://0xsimao.com/findings/codeup-ownable-codeup-erc20-removed) |
| Info | Unused `TransferFailed` error in `CodeupERC20` | [read it](https://0xsimao.com/findings/codeup-transfer-failed-codeup-erc20) |

## Ojo Network

Three Sigma · Oracles · 2024-10-16

[protocol](https://www.ojo.network/)

Report not published.

## stakeup bloomv2

Cantina · Treasury-bill yield stablecoin · 2024-10-07

[contest](https://cantina.xyz/competitions/61087007-c7e9-4c4e-9d90-4e118933fecf)

10 findings. The platform has not published this contest's findings.

## mev commit

Cantina · Execution preconfirmations · 2024-10-01

[contest](https://cantina.xyz/competitions/4ee8716d-3e0e-4f59-b90d-aa56bf3b484c)

8 findings. The platform has not published this contest's findings.

## IOP | Swaylend

Immunefi · Lending on Fuel · 2024-10-01

[contest](https://immunefi.com/audit-competition/iop-swaylend)

4 findings. The platform has not published this contest's findings.

## RedStone

Cantina · Oracle · 2024-09-24

[contest](https://cantina.xyz/competitions/8337db39-e04e-470d-8090-0cfb9a7ec2dd)

4 findings. The platform has not published this contest's findings.

## Saffron Lido Vaults

Sherlock · Staking · 2024-09-16

[contest](https://audits.sherlock.xyz/contests/509)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | `totalEarnings` is incorrect when withdrawing after ending which will withdraw too many funds leaving the `Vault` insolvent | [read it](https://0xsimao.com/findings/saffron-lido-vaults-ending-withdraw-leaving-insolvent) |
| High | The incorrect accounting of protocol fee will cause double charging fee and wrong distribution of earnings for variable users | [read it](https://0xsimao.com/findings/saffron-lido-vaults-accounting-fee-double-charging) |
| Medium | `LidoVault::vaultEndedWithdraw` doesn't take into consideration income withdrawals before slashing, blocking variable users from withdrwing their income | [read it](https://0xsimao.com/findings/saffron-lido-vaults-withdraw-withdrawals-slashing-withdrwing) |
| Medium | Withdrawing after a slash event before the vault has ended will decrease `fixedSidestETHOnStartCapacity` by less than it should, so following users will withdraw more their initial deposit | [read it](https://0xsimao.com/findings/saffron-lido-vaults-slash-eth-withdraw-deposit) |
| Medium | Attacker will DoS `LidoVault` up to 36 days which will ruin expected apr for all parties involved | [read it](https://0xsimao.com/findings/saffron-lido-vaults-lido-ruin-parties-involved) |

## Royco Protocol

Cantina · On-chain incentive markets · 2024-09-13

[contest](https://cantina.xyz/competitions/fadb5a8f-e39c-4a6b-89f6-a03858bb8602)

3 findings. The platform has not published this contest's findings.

## Flayer

Sherlock · NFT liquidity · 2024-09-02

[contest](https://audits.sherlock.xyz/contests/468)

3 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | The health of a ```ProtectedListing``` is incorrectly calculated if the ```tokenTaken``` has be changed through ```ProtectedListings::adjustPosition()```. | [read it](https://0xsimao.com/findings/flayer-health-through-listings-adjust) |
| High | Lister is overpaying during the cancel of his listing on ```Listings::cancelListings()```. | [read it](https://0xsimao.com/findings/flayer-lister-overpaying-his-listings) |
| Medium | In the unlockProtectedListing() function, the interest that was supposed to be distributed to LP holders was instead burned. | [read it](https://0xsimao.com/findings/flayer-listing-interest-supposed-burned) |

## Cork Protocol

Sherlock · Derivatives · 2024-08-29

[contest](https://audits.sherlock.xyz/contests/506)

15 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Lack of slippage protection leads to loss of protocol funds | [read it](https://0xsimao.com/findings/cork-protocol-lack-slippage-protection-protocol) |
| High | Users redeeming early will withdraw `Ra` without decreasing the amount locked, which will lead to stolen funds when withdrawing after expiry | [read it](https://0xsimao.com/findings/cork-protocol-redeeming-withdraw-locked-stolen) |
| High | `VaultPoolLib::reserve()` will store the `Pa` not attributed to user withdrawals incorrectly and leave in untracked once it expires again | [read it](https://0xsimao.com/findings/cork-protocol-attributed-withdrawals-untracked-expires) |
| High | FlashSwapRouter::emptyReserve()  and FlashSwapROuter::emptyReservePartial() functions return incorrect values | [read it](https://0xsimao.com/findings/cork-protocol-flash-empty-outer-partial) |
| High | Incorrect redeemAmount Is Accounted Due To Not Accounting For The  Exchange Rate | [read it](https://0xsimao.com/findings/cork-protocol-redeem-accounted-accounting-exchange) |
| High | Incoming Redemption Assets not being tracked when repurchase is called | [read it](https://0xsimao.com/findings/cork-protocol-incoming-redemption-tracked-repurchase) |
| High | Users will steal excess funds from the Vault due to `VaultPoolLib::redeem()` not always decreasing `self.withdrawalPool.raBalance` and `self.withdrawalPool.paBalance` | [read it](https://0xsimao.com/findings/cork-protocol-steal-excess-redeem-withdrawal) |
| High | Wrong accounting of locked RA when repurchasing DS+PA with RA | [read it](https://0xsimao.com/findings/cork-protocol-wrong-accounting-locked-repurchasing) |
| High | Admin new issuance or user calling `Vault::redeemExpiredLv()` after `Psm::redeemWithCt()` will lead to stuck funds when trying to withdraw | [read it](https://0xsimao.com/findings/cork-protocol-issuance-redeem-stuck-withdraw) |
| High | Attackers will steal the reserve from the `Vault` by receiving `ra` in `FlashSwapRouter::__swapDsforRa()` | [read it](https://0xsimao.com/findings/cork-protocol-steal-receiving-flash-dsfor) |
| Medium | Admin will not be able to only pause deposits in the `Vault` due to incorrect check leading to DoSed withdrawals | [read it](https://0xsimao.com/findings/cork-protocol-able-pause-deposits-withdrawals) |
| Medium | Admin will not be able to upgrade the smart contracts, breaking core functionality and rendering the upgradeable contracts useless | [read it](https://0xsimao.com/findings/cork-protocol-upgrade-functionality-rendering-upgradeable) |
| Medium | Withdrawing all `lv` before expiry will lead to lost funds in the Vault | [read it](https://0xsimao.com/findings/cork-protocol-withdrawing-expiry-lost-funds) |
| Medium | Rebasing tokens are not supported contrary to the readme and will lead to loss of funds | [read it](https://0xsimao.com/findings/cork-protocol-rebasing-supported-contrary-readme) |
| Medium | Providing liquidity to the AMM does not check the return value of actually provided tokens leading to locked funds. | [read it](https://0xsimao.com/findings/cork-protocol-providing-actually-provided-locked) |

## Rumpel Point Tokenization Protocol

Sherlock · Smart wallet · 2024-08-26

[contest](https://audits.sherlock.xyz/contests/494)

No findings.

## Maple Finance Syrup

Three Sigma · Permissionless lending · 2024-08-23

[protocol](https://maple.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-08-23-maple-finance-syrup.pdf)

5 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| Low | Deadline parameter in SyrupUserActions::_swapViaBalancer() could be set to minimize MEV | [read it](https://0xsimao.com/findings/maple-finance-syrup-balancer-swap-deadline) |
| Info | Extra spaces found in some instances of the codebase | [read it](https://0xsimao.com/findings/maple-finance-syrup-extra-spaces) |
| Info | Duplicated slippage check in SyrupUserActions | [read it](https://0xsimao.com/findings/maple-finance-syrup-duplicated-slippage-check) |
| Info | Duplicated _permit() function | [read it](https://0xsimao.com/findings/maple-finance-syrup-duplicated-permit) |
| Info | Immutable variables are emitted in events | [read it](https://0xsimao.com/findings/maple-finance-syrup-immutable-event-emissions) |

## Winnables Raffles

Sherlock · Raffle · 2024-08-16

[contest](https://audits.sherlock.xyz/contests/516)

6 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Users will lock raffle prizes on the `WinnablesPrizeManager` contract by calling `WinnablesTicketManager::propagateRaffleWinner` with wrong CCIP inputs | [read it](https://0xsimao.com/findings/winnables-raffles-lock-propagate-ccip-inputs) |
| High | Attacker will prevent any raffles by calling `WinnablesTicketManager::cancelRaffle` before admin starts raffle | [read it](https://0xsimao.com/findings/winnables-raffles-raffles-winnables-raffle-starts) |
| High | Method refundPlayers doesn't update _lockedETH in WinnableTicketManager | [read it](https://0xsimao.com/findings/winnables-raffles-refund-locked-eth-winnable) |
| Medium | Admin can unrestrictedly affect the odds of a raffle by setting themselves up with role(1) in `WinnablesTicket` | [read it](https://0xsimao.com/findings/winnables-raffles-unrestrictedly-affect-odds-themselves) |
| Medium | Admin can prevent raffle winner from claiming their reward | [read it](https://0xsimao.com/findings/winnables-raffles-raffle-winner-claiming-reward) |
| Medium | Users buying too many tickets will DoS them and the protocol if they are the winner due to OOG | [read it](https://0xsimao.com/findings/winnables-raffles-buying-tickets-winner-oog) |

## IOP | ThunderNFT

Immunefi · NFT marketplace on Fuel · 2024-08-12

[contest](https://immunefi.com/audit-competition/thundernft-iop)

3 findings. The platform has not published this contest's findings.

## Blast Ido Pools

Three Sigma · IDO launchpad · 2024-08-07

[protocol](https://docs.blastup.io/blastup-docs) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-08-07-blast-ido-pools.pdf)

13 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | `MultiplierContract::proposeMultipleUpdates()` updates `maxLevel` before executing the update | [read it](https://0xsimao.com/findings/blast-ido-pools-multiplier-propose-multiple-executing) |
| High | Funding cap in `IDOPoolAbstract::_basicParticipationCheck()` is imprecise and can lead to excessive tokens sold | [read it](https://0xsimao.com/findings/blast-ido-pools-participation-imprecise-excessive-sold) |
| High | Cancelling rounds after finalizing will lead to incorrect `globalTokenAllocPerIDORound` tracking | [read it](https://0xsimao.com/findings/blast-ido-pools-finalizing-alloc-round-tracking) |
| High | Rank and multiplier of a user can not be set if the user is registered for `MetaIDO` by the admin | [read it](https://0xsimao.com/findings/blast-ido-pools-rank-multiplier-registered-meta) |
| Medium | `IDOPoolAbstract::withdrawSpareIDO()` does not take into account that several rounds may use the same `IdoToken` | [read it](https://0xsimao.com/findings/blast-ido-pools-withdraw-spare-several-rounds) |
| Medium | `fyToken` contribution limits are incorrect as they compare `fyToken` and `buyToken` amounts with `idoSize` in `idoToken` units | [read it](https://0xsimao.com/findings/blast-ido-pools-contribution-limits-compare-buy) |
| Medium | `IDOPoolAbstract` does not deal with yield and gas accrued on Blast | [read it](https://0xsimao.com/findings/blast-ido-pools-yield-gas-accrued-blast) |
| Low | Incorrect `RefundClaim` event due to deleting `idoConfig.accountPositions[msg.sender]` | [read it](https://0xsimao.com/findings/blast-ido-pools-refund-deleting-config-positions) |
| Low | Rounds in `IDOPoolAbstract::manageRoundToMetaIDO()` can be overriden | [read it](https://0xsimao.com/findings/blast-ido-pools-manage-round-meta-overriden) |
| Low | Use of `address.transfer` instead of the recommended `address.call{value: amount}("")` | [read it](https://0xsimao.com/findings/blast-ido-pools-transfer-recommended-call-value) |
| Info | Null transfers in `IDOPoolAbstract::_depositToTreasury()` could be skipped | [read it](https://0xsimao.com/findings/blast-ido-pools-null-transfers-deposit-skipped) |
| Info | `IDORoundConfig.idoPrice` could have a comment somewhere specifying the units for better readability | [read it](https://0xsimao.com/findings/blast-ido-pools-round-price-somewhere-specifying) |
| Info | Missing `disableInitializers()` call in `StandardIDOPool::constructor()` | [read it](https://0xsimao.com/findings/blast-ido-pools-disable-initializers-standard-constructor) |

## Exactly Protocol Update - Staking Contract II

Sherlock · Staking · 2024-07-22

[contest](https://audits.sherlock.xyz/contests/396)

12 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Depositing to another receiver othan than `msg.sender` will lead to stuck funds by increasing `avgStart` without claiming | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-othan-stuck-increasing-avg) |
| Medium | Liquidations will leave dust when repaying expired maturities, making it impossible to clear bad debt putting the protocol at a risk of insolvency | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-liquidations-dust-debt-insolvency) |
| Medium | Liquidator will leave a pool with unassigned earnings on `Market::clearBadDebt()` free to claim for anyone when the repaid maturity is not the last | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-liquidator-clear-debt-repaid) |
| Medium | Some bad debt will not be cleared when it should which will cause accrual of bad debt decreasing the protocol's solvency | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-debt-cleared-accrual-solvency) |
| Medium | Precision Loss in `notifyRewardAmount` Function Causes Unclaimable RewardToken | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-precision-notify-reward-unclaimable) |
| Medium | Attackers will reset `avgStart` of any user making rewards stuck for longer and get lost to savings | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-avg-rewards-stuck-longer) |
| Medium | Frozen/paused Market that is harvested from in StakedEXA will DoS deposits leading to loss of yield | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-paused-harvested-deposits-yield) |
| Medium | Setting a new market will make depositing to the market impossible when harvesting, DoSing deposits | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-impossible-harvesting-sing-deposits) |
| Medium | Market utilization ratio near 100% will DoS deposits as harvest tries to withdraw and reverts | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-deposits-harvest-withdraw-reverts) |
| Medium | Anyone will DoS setting a new rewards duration which harms the protocol/users as they will receive too much or too little rewards | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-rewards-duration-harms-little) |
| Medium | Having no deposits in `StakedEXA` will lead to stuck rewards when harvesting | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-deposits-stuck-rewards-harvesting) |
| Medium | Liquidating maturies with unassigned earnings will not take into account floating assets increase leading to loss of funds | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-ii-liquidating-maturies-unassigned-floating) |

## Orange

Three Sigma · Cross-chain bridge · 2024-07-15

[protocol](https://www.orangeweb3.com/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-07-15-orange.pdf)

17 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | Balance check in Vault::withdraw() does not take fees into account | [read it](https://0xsimao.com/findings/orange-balance-withdraw-fees-account) |
| High | address.transfer is used in the codebase, which could lead to stuck funds | [read it](https://0xsimao.com/findings/orange-address-transfer-codebase-stuck) |
| High | Equality check should be performed for fees, not >= as it can lead to users sending more fees than supposed | [read it](https://0xsimao.com/findings/orange-equality-fees-sending-supposed) |
| Medium | Domain separator calculation is not fork safe | [read it](https://0xsimao.com/findings/orange-domain-separator-fork-safe) |
| Low | Ownership in BRC20Factory could be transferred using a 2 step procedure, similarly to Vault | [read it](https://0xsimao.com/findings/orange-ownership-transferred-procedure-similarly) |
| Low | Token addresses are not validated in BRC20Factory and Vault, so users can use incorrect tokens | [read it](https://0xsimao.com/findings/orange-addresses-validated-brc20-factory) |
| Low | BRC20Factory::burn() could validate the receiver length | [read it](https://0xsimao.com/findings/orange-burn-validate-receiver-length) |
| Low | BRC20Factory::addSigner() and Vault::addSigner() must not allow adding the zero address as a signer | [read it](https://0xsimao.com/findings/orange-brc20-signer-adding-zero) |
| Low | Fee event is missing in the constructors of BRC20Factory and Vault | [read it](https://0xsimao.com/findings/orange-fee-event-constructors-brc20) |
| Low | BRC20Factory constructor is missing a duplicate check | [read it](https://0xsimao.com/findings/orange-brc20-factory-constructor-duplicate) |
| Info | Checks effects interactions pattern is now always followed | [read it](https://0xsimao.com/findings/orange-effects-interactions-now-followed) |
| Info | BRC20Factory and Vault do different checks when removing signers | [read it](https://0xsimao.com/findings/orange-brc20-different-removing-signers) |
| Info | Storage variables can be cached to save gas | [read it](https://0xsimao.com/findings/orange-storage-variables-cached-gas) |
| Info | BRC20 parameters should be passed as arguments to the constructor of BRC20 to save gas | [read it](https://0xsimao.com/findings/orange-parameters-passed-arguments-gas) |
| Info | Signer duplicate check can be performed by requiring signers being sent ordered | [read it](https://0xsimao.com/findings/orange-signer-requiring-signers-ordered) |
| Info | authorized mapping is not required if the indexes mapping stores the indexes + 1 | [read it](https://0xsimao.com/findings/orange-authorized-required-indexes-stores) |
| Info | Reentrancy guard can be implemented with a uint256 to save gas | [read it](https://0xsimao.com/findings/orange-reentrancy-guard-implemented-gas) |

## Keyring II

Three Sigma · Zero-knowledge compliance · 2024-07-10

[protocol](https://www.keyring.network/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-07-10-keyring-ii.pdf)

12 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | Credentials can be manipulated | [read it](https://0xsimao.com/findings/keyring-ii-credentials-manipulated) |
| High | RsaVerifyOptimized sets the size of the key to 1024 bits, which is unsafe | [read it](https://0xsimao.com/findings/keyring-ii-verify-1024-bits-unsafe) |
| Medium | RsaVerifyOptimized::pkcs1Sha256() modified the original code incorrectly in one instance | [read it](https://0xsimao.com/findings/keyring-ii-pkcs1-sha256-modified-original) |
| Low | KeyringCoreV2Base::collectFees() should use Address::sendValue() instead of address.transfer() | [read it](https://0xsimao.com/findings/keyring-ii-keyring-fees-send-transfer) |
| Low | Missing admin change events | [read it](https://0xsimao.com/findings/keyring-ii-missing-admin-change-events) |
| Low | KeyringCoreV2Base could use a 2 step admin transfer mechanism | [read it](https://0xsimao.com/findings/keyring-ii-keyring-step-transfer-mechanism) |
| Info | KeyringCoreV2Base::_createCredential() could use currentTime instead of block.timestamp on the creatBefore check | [read it](https://0xsimao.com/findings/keyring-ii-credential-current-timestamp-creat) |
| Info | KeyringCoreV2Base::blacklistEntity() and KeyringCoreV2Base::unblacklistEntity() could check that the addresses are not already set | [read it](https://0xsimao.com/findings/keyring-ii-blacklist-entity-unblacklist-addresses) |
| Info | Admin checks in KeyringCoreV2Base could be placed in a modifier to increase readability and reduce code duplication | [read it](https://0xsimao.com/findings/keyring-ii-placed-readability-reduce-duplication) |
| Info | KeyringCoreV2Base::registerKey() could check that validTo is equal to or bigger than block.timestamp | [read it](https://0xsimao.com/findings/keyring-ii-register-equal-bigger-timestamp) |
| Info | Functions can be marked external when only called from other contracts | [read it](https://0xsimao.com/findings/keyring-ii-marked-external-called-contracts) |
| Info | Some natspec comments in KeyringCoreV2Base are outdated | [read it](https://0xsimao.com/findings/keyring-ii-natspec-comments-keyring-outdated) |

## Layer3

Three Sigma · Governance token · 2024-07-06

[protocol](https://layer3.xyz/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-07-06-layer3.pdf)

No findings.

## Mitosis

Three Sigma · Cross-chain liquidity layer 1 · 2024-06-25

[protocol](https://mitosis.org/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-06-25-mitosis.pdf)

32 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | BasicVault::_redeem() burns newAmount but redeems amount, allowing attackers to drain the vault | [read it](https://0xsimao.com/findings/mitosis-redeem-burns-redeems-drain) |
| High | BasicVault is incompatible with fee-on-transfer tokens | [read it](https://0xsimao.com/findings/mitosis-basic-incompatible-fee-transfer) |
| Medium | Metadata is not set in Cap, which is required by the inherited Router to specify gas limit to the mailbox | [read it](https://0xsimao.com/findings/mitosis-metadata-inherited-gas-mailbox) |
| Medium | StrategyExecutor::disableStrategy() disables the wrong strategy | [read it](https://0xsimao.com/findings/mitosis-executor-disable-disables-wrong) |
| Medium | RedeemQueue::getAvailableResolveRange() incorrectly returns false if from == count - 1 | [read it](https://0xsimao.com/findings/mitosis-redeem-queue-resolve-range) |
| Medium | BasicVault::_redeem() does not correctly deal with a disabled redeem queue after it was enabled | [read it](https://0xsimao.com/findings/mitosis-redeem-correctly-queue-enabled) |
| Medium | BasicVault::_deposit() should always resolve with idle balance as the redeem queue may be disabled with requests pending | [read it](https://0xsimao.com/findings/mitosis-deposit-resolve-redeem-queue) |
| Low | Protocol should disable renouncing ownership if it is never intended | [read it](https://0xsimao.com/findings/mitosis-disable-renouncing-ownership-intended) |
| Low | The StrategyExecutor can remain in a paused state if the owner renounces control while it's paused | [read it](https://0xsimao.com/findings/mitosis-remain-paused-renounces-control) |
| Low | BasicVault::manualRedeem() and BasicVault::manualDeposit() are inconsistent | [read it](https://0xsimao.com/findings/mitosis-manual-redeem-deposit-inconsistent) |
| Low | BasicVault::getRedeemRequestOf() will revert as the redeem requests are filled with the wrong indexes | [read it](https://0xsimao.com/findings/mitosis-redeem-revert-filled-indexes) |
| Low | Cap::receive() does not place restrictions in the sender, which may lead to donations | [read it](https://0xsimao.com/findings/mitosis-place-restrictions-sender-donations) |
| Low | _msgSender() is mixed with msg.sender | [read it](https://0xsimao.com/findings/mitosis-msg-sender-mixed) |
| Info | Adopt named mappings for clarity | [read it](https://0xsimao.com/findings/mitosis-adopt-named-mappings-clarity) |
| Info | Linea does not support PUSH0 | [read it](https://0xsimao.com/findings/mitosis-linea-support-push0) |
| Info | BasicVaultFactory::createVault() inconsistent already existing vault check | [read it](https://0xsimao.com/findings/mitosis-create-inconsistent-already-existing) |
| Info | Initializable constracts should call _disableInitializers() in the constructor instead of using the initializer modifier | [read it](https://0xsimao.com/findings/mitosis-initializable-constracts-initializers-initializer) |
| Info | pragma abicoder v2; is turned on by default after a certain solidity version | [read it](https://0xsimao.com/findings/mitosis-pragma-abicoder-turned-version) |
| Info | RedeemQueue::isResolved() resolvedCount always returns requestIds.length | [read it](https://0xsimao.com/findings/mitosis-redeem-queue-resolved-count) |
| Info | RedeemQueue::findOffsetIndex() does not check the last index | [read it](https://0xsimao.com/findings/mitosis-redeem-queue-offset-index) |
| Info | Structs in RedeemQueue are out of order and should all be placed at the top | [read it](https://0xsimao.com/findings/mitosis-structs-redeem-queue-top) |
| Info | RedeemQueue could be optimized | [read it](https://0xsimao.com/findings/mitosis-redeem-queue-optimized) |
| Info | RedeemQueue::get() reverts due to underflow when it should revert and throw the correct error | [read it](https://0xsimao.com/findings/mitosis-redeem-queue-reverts-underflow) |
| Info | Solidity types uint256 are never negative | [read it](https://0xsimao.com/findings/mitosis-solidity-types-uint256-negative) |
| Info | BasicVault::_resolveWithIdleBalance() can return before calculating _idleBalance() to save gas | [read it](https://0xsimao.com/findings/mitosis-resolve-idle-calculating-gas) |
| Info | Storage variables can be cached to save gas | [read it](https://0xsimao.com/findings/mitosis-storage-variables-cached-gas) |
| Info | decimals() is not part of the ERC20 standard and not all tokens may implement it as expected, which may cause initialize() to fail | [read it](https://0xsimao.com/findings/mitosis-decimals-part-erc20-initialize) |
| Info | Cap::_checkRemoteStateAndAdvance() may be optimized by returning early as soon as a different epoch is found in a remote domain | [read it](https://0xsimao.com/findings/mitosis-remote-returning-soon-epoch) |
| Info | The domain with 0 index in Cap::_checkRemoteStateAndAdvance() is not checked for equality | [read it](https://0xsimao.com/findings/mitosis-index-remote-advance-equality) |
| Info | The current epoch will never advance if there are no other domains | [read it](https://0xsimao.com/findings/mitosis-current-epoch-advance-domains) |
| Info | Cap::setEpochCap() may add a stale cap | [read it](https://0xsimao.com/findings/mitosis-cap-epoch-add-stale) |
| Info | In AggregateHook, several if (newAmount == 0) checks are ambiguous | [read it](https://0xsimao.com/findings/mitosis-aggregate-hook-several-ambiguous) |

## BendDAO

Code4rena · NFT lending · 2024-06-19

[protocol](https://www.benddao.xyz/) · [report](https://github.com/0xsimao/audits/blob/main/Code4rena/private-audits/2024-06-19-benddao.md)

8 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Mismatch between yield amount deposited in shares calculation and getAccountYieldBalance() | [read it](https://0xsimao.com/findings/benddao-mismatch-yield-deposited-shares) |
| High | Bad debt is never handled which places insolvency risks on BendDAO | [read it](https://0xsimao.com/findings/benddao-debt-places-insolvency-risks) |
| High | Users cannot unstake from YiedlETHStakingEtherfi.sol, because YieldAccount.sol is incompatible with ether.fi's WithdrawRequestNFT.sol | [read it](https://0xsimao.com/findings/benddao-unstake-eth-staking-yield) |
| High | Anyone can get the NFT collateral token after an Auction without bidding due to missing check on msg.sender | [read it](https://0xsimao.com/findings/benddao-nft-collateral-auction-bidding) |
| Medium | Unhandled request invalidation by the owner of Etherfi will lead to stuck debt | [read it](https://0xsimao.com/findings/benddao-unhandled-invalidation-stuck-debt) |
| Medium | Major insolvency risk in LiquidationLogic::executeCrossLiquidateERC721() due to not setting a maximum liquidation price | [read it](https://0xsimao.com/findings/benddao-insolvency-liquidation-liquidate-erc721) |
| Medium | It's impossible to retrieve collected fines from the yield staking contract | [read it](https://0xsimao.com/findings/benddao-collected-fines-yield-staking) |
| Medium | Borrower can prevent yield position repayment and closure by the bot | [read it](https://0xsimao.com/findings/benddao-yield-repayment-closure-bot) |

## Attackathon | Fuel Network

Immunefi · Modular execution layer · 2024-06-17

[contest](https://immunefi.com/audit-competition/fuel-network-attackathon)

1 findings. The platform has not published this contest's findings.

## DistrictOne

Three Sigma · Social money games · 2024-06-13

[protocol](https://districtone.io/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-06-13-districtone.pdf)

10 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | Claiming will fail for Ole and D1MemeToken if the overfunded ETH reverts | [read it](https://0xsimao.com/findings/districtone-meme-overfunded-eth-reverts) |
| High | Any signature is valid before the issuer address is set | [read it](https://0xsimao.com/findings/districtone-signature-valid-issuer-address) |
| Medium | FairLauncher::newFairLaunch() may be misconfigured | [read it](https://0xsimao.com/findings/districtone-fair-launcher-launch-misconfigured) |
| Medium | FairLauncher::participate() should allow specifying a minimum number of shares due to the overfund mechanism | [read it](https://0xsimao.com/findings/districtone-participate-specifying-shares-overfund) |
| Medium | FairLauncher inherits BlastNoYieldAdapter but will hold ETH | [read it](https://0xsimao.com/findings/districtone-inherits-blast-yield-eth) |
| Info | Erc20Utils::safeTransferFrom() assumes the tokens are transferred to this, which may not be the case | [read it](https://0xsimao.com/findings/districtone-erc20-utils-transfer-transferred) |
| Info | Deadline in Ole swap could be sent as a parameter to further prevent MEV | [read it](https://0xsimao.com/findings/districtone-deadline-ole-further-mev) |
| Info | Invite fees in FairLauncher::_calInviteFees() may be 0, in which case storage update could be skipped | [read it](https://0xsimao.com/findings/districtone-invite-fees-cal-storage) |
| Info | D1MemeTokens will be stuck whenever the merkle roots or the free claims are not fully claimed | [read it](https://0xsimao.com/findings/districtone-stuck-merkle-roots-claimed) |
| Info | TokenVault allows withdrawals using offchain logic, so the offchain service must take into consideration reorgs | [read it](https://0xsimao.com/findings/districtone-withdrawals-offchain-consideration-reorgs) |

## PoolTogether: The Prize Layer for DeFi

Sherlock · Raffle · 2024-05-16

[contest](https://audits.sherlock.xyz/contests/225) · [report](https://github.com/0xsimao/audits/blob/main/Sherlock/contests/2024-05-16-pooltogether-the-prize-layer-for-defi.md)

12 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Vault portion calculation in `PrizePool::getVaultPortion()` is incorrect as `_startDrawIdInclusive` has been erased | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-portion-prize-inclusive-erased) |
| High | Draw auction rewards likely exceed the available rewards, resulting in overpaying rewards or running into an `InsufficientReserve` error | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-rewards-exceed-running-insufficient) |
| Medium | Estimated prize draws in TieredLiquidityDistributor are off due to rounding down when calculating the sum, leading to incorrect prizes | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-estimated-draws-tiered-rounding) |
| Medium | `Claimers` can receive less `feePerClaim` than they should if some prizes are already claimed or if reverts because of a reverting hook | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-claimers-fee-reverts-hook) |
| Medium | Witnet is not available on some networks listed | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-witnet-available-networks-listed) |
| Medium | `DrawManager.canStartDraw` does not consider retried RNG requests when determining if a new draw auction can be started | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-retried-rng-determining-started) |
| Medium | `maxDeposit` doesn't comply with ERC-4626 | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-deposit-comply-erc-4626) |
| Medium | Gas Manipulation by Malicious Winners in claimPrizes Function | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-gas-manipulation-winners-prizes) |
| Medium | Price formula in `TpdaLiquidationPair._computePrice()` does not account for a jump in liquidatable balance | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-price-tpda-liquidation-compute) |
| Medium | The claimer's fee will be stolen by the winner | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-claimer-fee-stolen-winner) |
| Medium | Potential ETH Loss Due to transfer Usage in Requestor Contract on `zkSync` | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-eth-transfer-requestor-sync) |
| Medium | DoSed liquidations as `PrizeVault::liquidatableBalanceOf()` does not take into account the `mintLimit` when the token out is the asset | [read it](https://0xsimao.com/findings/pooltogether-the-prize-layer-for-defi-liquidations-prize-liquidatable-mint) |

## Arbitrum Bold

Code4rena · L2 · 2024-05-10

[contest](https://code4rena.com/audits/2024-05-arbitrum-bold)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Inconsistent sequencer unexpected delay in DelayBuffer may harm users calling forceInclusion() | [read it](https://0xsimao.com/findings/arbitrum-bold-sequencer-unexpected-force-inclusion) |

## safe extensions

Cantina · Safe modules and guards · 2024-05-06

[contest](https://cantina.xyz/competitions/d47f8096-8858-437d-a9f5-2fe85ac9b95e)

2 findings. The platform has not published this contest's findings.

## Renzo

Code4rena · Liquid restaking · 2024-04-30

[contest](https://code4rena.com/audits/2024-04-renzo)

6 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | ETH withdrawals from EigenLayer always fail due to `OperatorDelegator`'s nonReentrant `receive()` | [read it](https://0xsimao.com/findings/renzo-eth-withdrawals-delegator-reentrant) |
| High | Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps | [read it](https://0xsimao.com/findings/renzo-withdrawals-zero-slippage-fee) |
| High | DOS of `completeQueuedWithdrawal` when ERC20 buffer is filled | [read it](https://0xsimao.com/findings/renzo-dos-withdrawal-erc20-filled) |
| High | Incorrect withdraw queue balance in TVL calculation | [read it](https://0xsimao.com/findings/renzo-withdraw-queue-tvl-calculation) |
| Medium | Withdrawals can fail due to deposits reverting in `completeQueuedWithdrawal()` | [read it](https://0xsimao.com/findings/renzo-withdrawals-deposits-complete-withdrawal) |
| Medium | Withdrawals and Claims are meant to be pausable, but it is not possible in practice | [read it](https://0xsimao.com/findings/renzo-withdrawals-meant-pausable-practice) |

## Teller Finance

Sherlock · Lending · 2024-04-23

[contest](https://audits.sherlock.xyz/contests/295)

17 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | `_sendOrEscrowFunds` will brick LCG funds causing insolvency | [read it](https://0xsimao.com/findings/teller-finance-escrow-lcg-causing-insolvency) |
| High | `burnSharesToWithdrawEarnings` burns before math, causing the share value to increase | [read it](https://0xsimao.com/findings/teller-finance-burn-shares-withdraw-share) |
| High | liquidateDefaultedLoanWithIncentive sends the collateral to the wrong account | [read it](https://0xsimao.com/findings/teller-finance-liquidate-defaulted-incentive-collateral) |
| High | Anyone can steal pool shares from lender group if no-revert-on-failure tokens are used | [read it](https://0xsimao.com/findings/teller-finance-steal-shares-revert-failure) |
| High | Drained lender due to `LenderCommitmentGroup_Smart::acceptFundsForAcceptBid()` `_collateralAmount` by `STANDARD_EXPANSION_FACTOR` multiplication | [read it](https://0xsimao.com/findings/teller-finance-bid-collateral-factor-multiplication) |
| High | `LenderCommitmentGroup_Smart` picks the wrong Uniswap price, allowing borrowing at a discount by swapping before withdrawing | [read it](https://0xsimao.com/findings/teller-finance-picks-uniswap-price-allowing) |
| High | Interest rate in `LenderCommitmentGroup_Smart` may be easily manipulated by depositing, taking a loan and withdrawing | [read it](https://0xsimao.com/findings/teller-finance-interest-easily-manipulated-taking) |
| Medium | Issue #497 'Add parameter to lender accept bid for MaxMarketFee' from previous audit is still present | [read it](https://0xsimao.com/findings/teller-finance-497-bid-fee-audit) |
| Medium | Incorrect selector in `FlashRolloverLoan_G5::_acceptCommitment()` does not match `SmartCommitmentForwarder::acceptCommitmentWithRecipient()` | [read it](https://0xsimao.com/findings/teller-finance-rollover-match-forwarder-recipient) |
| Medium | `FlashRolloverLoan_G5` will fail for `LenderCommitmentGroup_Smart` due to `CollateralManager` pulling collateral from `FlashRolloverLoan_G5` | [read it](https://0xsimao.com/findings/teller-finance-flash-rollover-collateral-pulling) |
| Medium | `FlashRolloverLoan_G5` will not work for certain tokens due to not setting the approval to `0` after repaying a loan | [read it](https://0xsimao.com/findings/teller-finance-flash-rollover-approval-repaying) |
| Medium | Performing a direct multiplication in `_getPriceFromSqrtX96` will overflow for some uniswap pools | [read it](https://0xsimao.com/findings/teller-finance-performing-price-overflow-uniswap) |
| Medium | Missing `__Ownable_init()` call in `LenderCommitmentGroup_Smart::initialize()` | [read it](https://0xsimao.com/findings/teller-finance-ownable-init-commitment-initialize) |
| Medium | `LenderCommitmentGroup_Smart` does not use `mulDiv` when converting between token and share amounts, possibly leading to DoS or loss of funds | [read it](https://0xsimao.com/findings/teller-finance-mul-div-converting-share) |
| Medium | `LenderCommitmentGroup_Smart_test::addPrincipalToCommitmentGroup/burnSharesToWithdrawEarnings()` are vulnerable to slippage attacks | [read it](https://0xsimao.com/findings/teller-finance-burn-shares-withdraw-slippage) |
| Medium | APRs are lower than they should | [read it](https://0xsimao.com/findings/teller-finance-lower-they) |
| Medium | `LenderCommitmentGroup` pools will have incorrect exchange rate when fee-on-transfer tokens are used | [read it](https://0xsimao.com/findings/teller-finance-pools-exchange-fee-transfer) |

## TITLES Publishing Protocol

Sherlock · Referential NFT publishing · 2024-04-22

[contest](https://audits.sherlock.xyz/contests/326)

8 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Users can exploit the batch minting feature to avoid paying minting fees for tokens | [read it](https://0xsimao.com/findings/titles-publishing-protocol-exploit-feature-avoid-fees) |
| High | Collection referrers will not receive their share of the minting fee | [read it](https://0xsimao.com/findings/titles-publishing-protocol-collection-referrers-share-fee) |
| Medium | Incorrect encoding of bytes for EIP712 digest in `TitleGraph` causes signatures generated by common EIP712 tools to be unusable | [read it](https://0xsimao.com/findings/titles-publishing-protocol-encoding-digest-tools-unusable) |
| Medium | New creators unable to update the royalty target and the fee route for their works | [read it](https://0xsimao.com/findings/titles-publishing-protocol-creators-unable-fee-works) |
| Medium | Incompatibility of Upgradeability Pattern in TitlesGraph Contract | [read it](https://0xsimao.com/findings/titles-publishing-protocol-incompatibility-upgradeability-titles-graph) |
| Medium | FeeManager's admin cannot grant or revoke any role | [read it](https://0xsimao.com/findings/titles-publishing-protocol-fee-cannot-grant-revoke) |
| Medium | Malicious users can block creators from acknowledging or deacknowledging an edge | [read it](https://0xsimao.com/findings/titles-publishing-protocol-creators-acknowledging-deacknowledging-edge) |
| Medium | Signature is malleable | [read it](https://0xsimao.com/findings/titles-publishing-protocol-signature-malleable) |

## Exactly Protocol Update - Staking Contract

Sherlock · Staking · 2024-04-22

[contest](https://audits.sherlock.xyz/contests/247)

11 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | The Rounding Done in Protocol's Favor Can Be Weaponized to Drain the Protocol | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-rounding-favor-weaponized-drain) |
| High | Unassigned pool earnings can be stolen when a maturity borrow is liquidated by depositing at maturity with 1 principal | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-unassigned-stolen-borrow-liquidated) |
| Medium | `TARGET_HEALTH` calculation does not consider the adjust factors of the picked seize and repay markets | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-factors-seize-repay-markets) |
| Medium | `Market::liquidate()` will not work when most of the liquidity is borrowed due to wrong liquidator `transferFrom()` order | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-liquidate-borrowed-liquidator-transfer) |
| Medium | Utilization rates are 0 when average assets are 0, which may be used to game maturity borrows / deposits / withdrawals | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-average-borrows-deposits-withdrawals) |
| Medium | Liquidation does not prioritize lowest LTV tokens | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-liquidation-prioritize-lowest-ltv) |
| Medium | Expired maturities longer than `FixedLib.INTERVAL` with unaccrued earnings may be arbitraged and/or might lead to significant bad debt creation | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-unaccrued-arbitraged-debt-creation) |
| Medium | `rewardData.releaseRate` is incorrectly calculated on `RewardsController::config()` when `block.timestamp > start` and `rewardData.lastConfig != rewardData.start` | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-reward-release-rewards-timestamp) |
| Medium | Manipulation of the floating debt by updating `floatingBackupBorrowed` | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-manipulation-debt-backup-borrowed) |
| Medium | Rewards can disappear when new rewards are distributed in the RewardsController. | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-rewards-disappear-distributed-controller) |
| Medium | Profitable liquidations and accumulation of bad debt due to earnings accumulator not being triggered before liquidating | [read it](https://0xsimao.com/findings/exactly-protocol-update-staking-contract-liquidations-accumulation-debt-accumulator) |

## Maple Finance III

Three Sigma · Institutional lending · 2024-04-10

[protocol](https://maple.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-04-10-maple-finance-iii.pdf)

35 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | Fixed term loans can be deployed with a wrong fee manager and possibly steal all funds. | [read it](https://0xsimao.com/findings/maple-finance-iii-loans-deployed-fee-steal) |
| High | Pool Delegates can set a really high origination fee and steal all pool funds. | [read it](https://0xsimao.com/findings/maple-finance-iii-really-origination-fee-steal) |
| High | Pool Delegates can steal all the pool's funds by setting a malicious Withdrawal Manager. | [read it](https://0xsimao.com/findings/maple-finance-iii-delegates-steal-setting-withdrawal) |
| High | Pool Delegates can set an unreasonably large delegate management fee rate at anytime | [read it](https://0xsimao.com/findings/maple-finance-iii-unreasonably-delegate-fee-anytime) |
| High | Liquidation can be finished without calling triggerDefault() (and repossessing the loan) if pool delegate or governor call finishCollateralLiquidation(...) after impairment. | [read it](https://0xsimao.com/findings/maple-finance-iii-liquidation-repossessing-delegate-collateral) |
| High | Malicious refinancer danger due to fixed term loan upgrades. | [read it](https://0xsimao.com/findings/maple-finance-iii-refinancer-danger-term-upgrades) |
| Medium | Open term loans can be created with zero platform service fee if borrowers create them right after a pool has been deployed. | [read it](https://0xsimao.com/findings/maple-finance-iii-zero-platform-fee-right) |
| Medium | fundLoan() can be DoSed if returnFunds() is called before it. | [read it](https://0xsimao.com/findings/maple-finance-iii-fund-sed-return-called) |
| Medium | A pool delegate should not be allowed to be a borrower | [read it](https://0xsimao.com/findings/maple-finance-iii-pool-delegate-borrower) |
| Medium | MapleGlobals, activatePoolManager() has no check that the pool manager is actually a valid pool manager. | [read it](https://0xsimao.com/findings/maple-finance-iii-globals-activate-actually-valid) |
| Medium | DoS attack if assets are transferred before a fundLoan() call. | [read it](https://0xsimao.com/findings/maple-finance-iii-attack-assets-transferred-fund) |
| Medium | Pool Delegates can accidentally lock out of their funds LPs in the middle of redeeming. | [read it](https://0xsimao.com/findings/maple-finance-iii-accidentally-lock-middle-redeeming) |
| Low | MapleLoan, proposeNewTerms() could have a check for duplicate selectors. | [read it](https://0xsimao.com/findings/maple-finance-iii-propose-terms-duplicate-selectors) |
| Low | MapleLoan, skim() has no zero address transfer check. | [read it](https://0xsimao.com/findings/maple-finance-iii-skim-zero-address-transfer) |
| Low | In MapleLoanInitializer, the Borrower can choose a different fundsAsset than the lender. | [read it](https://0xsimao.com/findings/maple-finance-iii-initializer-borrower-choose-different) |
| Low | Borrowers can prevent MapleLoanInitializer from initializing a loan by using a vanity address. | [read it](https://0xsimao.com/findings/maple-finance-iii-borrowers-initializer-initializing-vanity) |
| Low | Consider using a time lock on critical permissioned functions. | [read it](https://0xsimao.com/findings/maple-finance-iii-consider-lock-critical-permissioned) |
| Low | In MapleGlobals, there is no check in the dataHash argument when unscheduling a call. | [read it](https://0xsimao.com/findings/maple-finance-iii-globals-hash-argument-unscheduling) |
| Low | Consider adding a check to ensure that fees, delegate cover and so on have been explicitly set. | [read it](https://0xsimao.com/findings/maple-finance-iii-ensure-fees-delegate-explicitly) |
| Low | In PoolManager, setOpenToPublic(), there is no way to unset openToPublic. | [read it](https://0xsimao.com/findings/maple-finance-iii-open-public-way-unset) |
| Low | Throughout code-base: missing address checks. | [read it](https://0xsimao.com/findings/maple-finance-iii-throughout-code-address-checks) |
| Info | MapleLoan variables read from storage more than once. | [read it](https://0xsimao.com/findings/maple-finance-iii-maple-variables-read-storage) |
| Info | MapleLoanStorage storage slot optimization. | [read it](https://0xsimao.com/findings/maple-finance-iii-maple-storage-slot-optimization) |
| Info | MapleLoan change the order of require to save on gas. | [read it](https://0xsimao.com/findings/maple-finance-iii-change-require-save-gas) |
| Info | In PoolManager, requestFunds(...) repeated variable fetching from storage. | [read it](https://0xsimao.com/findings/maple-finance-iii-repeated-variable-fetching-storage) |
| Info | In MapleLoanFactory, isLoan has the same functionality of isInstance and thus can be removed. | [read it](https://0xsimao.com/findings/maple-finance-iii-functionality-instance-thus-removed) |
| Info | LoanManager code optimizations: no need to load payment struct from storage if loan is unimpaired. | [read it](https://0xsimao.com/findings/maple-finance-iii-optimizations-load-storage-unimpaired) |
| Info | LoanManager code optimizations: redundant impairment functions. | [read it](https://0xsimao.com/findings/maple-finance-iii-optimizations-redundant-impairment-functions) |
| Info | Throughout code base: use Solidity native errors implementation instead of string errors. | [read it](https://0xsimao.com/findings/maple-finance-iii-solidity-native-implementation-string) |
| Info | open-term-loan-private: check dateFunded!=0 first to save gas. | [read it](https://0xsimao.com/findings/maple-finance-iii-term-date-funded-gas) |
| Info | pool-v2-private: cache list length in memory and uncheck i_ to save gas. | [read it](https://0xsimao.com/findings/maple-finance-iii-private-cache-uncheck-gas) |
| Info | Throughout code-base: Homogenize how access control is done. | [read it](https://0xsimao.com/findings/maple-finance-iii-homogenize-access-control-done) |
| Info | Missing documentation for MapleLoan, SetPendingLender and AcceptLender being implemented on MapleLoan but not on LoanManager. | [read it](https://0xsimao.com/findings/maple-finance-iii-documentation-pending-accept-implemented) |
| Info | Multiple documentation fixes throughout the repository. | [read it](https://0xsimao.com/findings/maple-finance-iii-multiple-documentation-fixes-repository) |
| Info | globals-v2-private: typo in function name. | [read it](https://0xsimao.com/findings/maple-finance-iii-globals-private-typo-name) |

## Zivoe

Sherlock · Lending · 2024-04-08

[contest](https://audits.sherlock.xyz/contests/280)

4 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | `ZivoeYDL::earningsTrancheuse()` always assumes that `daysBetweenDistributions` have passed, which might not be the case | [read it](https://0xsimao.com/findings/zivoe-zivoe-ydl-trancheuse-distributions) |
| Medium | OCL_ZVE::pushToLockerMulti() will revert due to incorrect assert() statements when interacting with UniswapV2 | [read it](https://0xsimao.com/findings/zivoe-revert-assert-interacting-uniswap) |
| Medium | When APR late rate is lower than APR, an OCC locker bullet loan borrower can pay way less interests by calling the loan | [read it](https://0xsimao.com/findings/zivoe-occ-bullet-pay-interests) |
| Medium | Rewards are calculated as distributed even if there are no stakers, locking the rewards forever | [read it](https://0xsimao.com/findings/zivoe-rewards-distributed-stakers-locking) |

## Metazero II

Three Sigma · Omnichain RWA tokenisation · 2024-04-06

[protocol](https://metazero.gg/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-04-06-metazero-ii.pdf)

10 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | feesAccrued or staker principal may be sent as rewards if rewardRate and emissionEnd are not properly calculated | [read it](https://0xsimao.com/findings/metazero-ii-fees-rewards-reward-properly) |
| High | Increasing emissionEnd after the previous emissionEnd ended will yield full rewards according to newEmissionEnd - prevEmissionEnd | [read it](https://0xsimao.com/findings/metazero-ii-yield-full-rewards-according) |
| Low | getRemainingUnstakeTime() returns 0 if user has not unstaked | [read it](https://0xsimao.com/findings/metazero-ii-remaining-unstake-returns-unstaked) |
| Low | emissionStart has no effect, rewards will start accumulating starting on the first staker | [read it](https://0xsimao.com/findings/metazero-ii-effect-rewards-accumulating-starting) |
| Low | Missing some events | [read it](https://0xsimao.com/findings/metazero-ii-missing-events) |
| Info | Variables should be cached to memory to save gas | [read it](https://0xsimao.com/findings/metazero-ii-variables-cached-memory-gas) |
| Info | Custom errors should be used instead of require() statements to save gas | [read it](https://0xsimao.com/findings/metazero-ii-custom-require-statements-gas) |
| Info | completeUnstake() not following checks-effects-interactions pattern | [read it](https://0xsimao.com/findings/metazero-ii-complete-unstake-following-interactions) |
| Info | Constants should not be hardcoded | [read it](https://0xsimao.com/findings/metazero-ii-constants-hardcoded) |
| Info | Codebase is not using SafeERC20 | [read it](https://0xsimao.com/findings/metazero-ii-codebase-safe-erc20) |

## Vertex

Three Sigma · Hybrid orderbook DEX · 2024-04-03

Report not published.

## Keyring I

Three Sigma · Zero-knowledge compliance · 2024-03-22

[protocol](https://www.keyring.network/)

Report not published.

## Clip Finance II

Three Sigma · DeFi infrastructure · 2024-03-15

[protocol](https://www.clip.finance/)

Report not published.

## Singularity

Three Sigma · Private DeFi access · 2024-02-26

[protocol](https://www.thesingularity.network/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-02-26-singularity.pdf)

42 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | In StakingAssetManager::lockERC20() the resulting note is created with asset instead of zkToken | [read it](https://0xsimao.com/findings/singularity-staking-lock-erc20-resulting) |
| High | MerkleRoot is not validated in all StakingAssetManager functions | [read it](https://0xsimao.com/findings/singularity-merkle-root-validated-staking) |
| High | Checks-effects-interations pattern is not always followed, which can be used to drain all tokens | [read it](https://0xsimao.com/findings/singularity-effects-interations-followed-drain) |
| High | Curve multi exchange does not validate assetIn and assetOut against route | [read it](https://0xsimao.com/findings/singularity-curve-validate-against-route) |
| High | DarkPoolAssetManager can be drained by looping over join(), joinSplit() or swap() with only some initial amount | [read it](https://0xsimao.com/findings/singularity-dark-looping-join-split) |
| High | Stuck ETH in Curve exchanges due to sending msg.value to the exchange instead of amountIn | [read it](https://0xsimao.com/findings/singularity-stuck-eth-curve-exchanges) |
| High | Reusing the same rho and pubKey in different deposits leads to lost tokens | [read it](https://0xsimao.com/findings/singularity-reusing-rho-pub-deposits) |
| High | Note footers should not be 0 in curveRemoveLiquidity() if the corresponding assetOuts are non null | [read it](https://0xsimao.com/findings/singularity-footers-curve-corresponding-outs) |
| High | UniswapLiquidityAssetManager::_validateCollectFeesArgs() validates nullifier instead of note footer | [read it](https://0xsimao.com/findings/singularity-uniswap-fees-validates-nullifier) |
| High | CurveAssetManagerHelper::_validateAssets() should check that the number of assets provided is smaller than the maximum of the pool | [read it](https://0xsimao.com/findings/singularity-curve-helper-validate-provided) |
| High | All curve params should be signed by the schnorr private key in the proof, or users may be griefed | [read it](https://0xsimao.com/findings/singularity-curve-schnorr-proof-griefed) |
| High | Curve multi exchange can be used to withdraw assets without paying fees | [read it](https://0xsimao.com/findings/singularity-curve-withdraw-paying-fees) |
| High | Anyone can deposit to DarkpoolAssetManager as the owner can be freely chosen without any implication | [read it](https://0xsimao.com/findings/singularity-deposit-darkpool-freely-implication) |
| High | Attackers can include other users nullifiers to make their funds stuck when adding liquidity to curve | [read it](https://0xsimao.com/findings/singularity-include-nullifiers-stuck-curve) |
| High | _addLiquidity() slippage is incorrectly set | [read it](https://0xsimao.com/findings/singularity-add-liquidity-slippage-incorrectly) |
| High | Anyone can frontrun a relayer interaction with the same arguments but a much higher/lower relayer fee | [read it](https://0xsimao.com/findings/singularity-frontrun-relayer-interaction-fee) |
| High | DarkpoolAssetManager::Split() into 2 equal amounts leads to lost funds | [read it](https://0xsimao.com/findings/singularity-darkpool-split-equal-amounts) |
| High | No support for fee on transfer tokens | [read it](https://0xsimao.com/findings/singularity-support-fee-transfer-tokens) |
| Medium | Curve pools should be whitelisted as some of them may not be 100% compatible | [read it](https://0xsimao.com/findings/singularity-curve-whitelisted-100-compatible) |
| Medium | Uniswap collect fees should skip collecting fees of one of the tokens if the amount is 0 | [read it](https://0xsimao.com/findings/singularity-uniswap-fees-skip-collecting) |
| Medium | Service fees should depend on asset | [read it](https://0xsimao.com/findings/singularity-service-fees-depend-asset) |
| Medium | CurveAddLiquidityAssetManager::curveAddLiquidity() does not deal correctly with isLegacy = 0b10 and ETH | [read it](https://0xsimao.com/findings/singularity-curve-legacy-0b10-eth) |
| Medium | Uniswap asset managers are missing slippage checks | [read it](https://0xsimao.com/findings/singularity-uniswap-managers-slippage-checks) |
| Medium | Some ETH transfers don't revert if they fail | [read it](https://0xsimao.com/findings/singularity-eth-transfers-don-revert) |
| Low | Decimals in ZKToken are not set to the underlying decimals, which will likely harm tvl calculations in aggregators | [read it](https://0xsimao.com/findings/singularity-decimals-underlying-calculations-aggregators) |
| Low | StakingOperator::setCollateralToken() will cause issues if it changes tokens relations that have already been set | [read it](https://0xsimao.com/findings/singularity-staking-collateral-changes-relations) |
| Low | Missing event in VerifierHub::setVerifier() | [read it](https://0xsimao.com/findings/singularity-event-verifier-hub-set) |
| Low | Setting note commitments, nullifiers and note footers used should revert if they are already set to prevent exploits | [read it](https://0xsimao.com/findings/singularity-commitments-nullifiers-footers-revert) |
| Low | ERC20AssetPool and ERC721AssetPool should have the nonReentrant modifier as ERC721 and some tokens have callbacks | [read it](https://0xsimao.com/findings/singularity-erc20-erc721-reentrant-callbacks) |
| Low | Generating numbers smaller than P by doing % P might be vulnerable | [read it](https://0xsimao.com/findings/singularity-generating-numbers-smaller-doing) |
| Low | MerkleTreeOperator::getMerklePath() will revert due to OOG after enough elements | [read it](https://0xsimao.com/findings/singularity-merkle-path-revert-elements) |
| Info | stakingAssetManager in ZKToken may be immutable as it is never changed | [read it](https://0xsimao.com/findings/singularity-staking-asset-immutable-changed) |
| Info | StakingOperator::_setUnlockWindow() checks if the times are negative, which is impossible | [read it](https://0xsimao.com/findings/singularity-staking-window-times-negative) |
| Info | StakingOperator does not set isUnlockWindowActive to true in the constructor if the flag passed is true | [read it](https://0xsimao.com/findings/singularity-staking-window-active-flag) |
| Info | Checks effects interactions pattern is not always followed | [read it](https://0xsimao.com/findings/singularity-effects-interactions-pattern-followed) |
| Info | Variables are initialized to 0 by default | [read it](https://0xsimao.com/findings/singularity-variables-initialized-default) |
| Info | UniswapLiquidityAssetManager::uniswapLiquidityProvision() could return tokenId | [read it](https://0xsimao.com/findings/singularity-uniswap-liquidity-provision-return) |
| Info | Spelling errors throughout the codebase | [read it](https://0xsimao.com/findings/singularity-spelling-errors-throughout-codebase) |
| Info | Unused noteCommitment parameter in UniswapRemoveLiquidityInputs struct | [read it](https://0xsimao.com/findings/singularity-parameter-uniswap-inputs-struct) |
| Info | Missing proof identifier, which could lead to using the same proof in another method | [read it](https://0xsimao.com/findings/singularity-proof-identifier-same-method) |
| Info | UniswapLiquidityAssetManager registers the note footer twice | [read it](https://0xsimao.com/findings/singularity-uniswap-registers-footer-twice) |
| Info | BaseAssetManager missing 0 address checks in the constructor | [read it](https://0xsimao.com/findings/singularity-asset-address-checks-constructor) |

## Ostium

Three Sigma · RWA perpetuals DEX · 2024-02-19

[protocol](https://www.ostium.com/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-02-19-ostium.pdf)

57 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | In OstiumTradingStorage, firstEmptyTradeIndex() and firstEmptyOpenLimitIndex() overwrite index 0 if not found | [read it](https://0xsimao.com/findings/ostium-storage-index-overwrite-found) |
| High | Liquidations can be prevented by updating the SL timeout before it expires | [read it](https://0xsimao.com/findings/ostium-liquidations-prevented-timeout-expires) |
| High | Uneven getPendingAccFundingFees() leading to wrong funding rate update | [read it](https://0xsimao.com/findings/ostium-uneven-acc-funding-fees) |
| High | Inability to Close Positions with Significant Positive PnL | [read it](https://0xsimao.com/findings/ostium-inability-close-positions-positive) |
| High | Oracle fees should be payed upfront to protect the protocol from failed performeUpkeep() calls | [read it](https://0xsimao.com/findings/ostium-oracle-fees-upfront-performe) |
| High | updatePair() is missing the pairOk() modifier | [read it](https://0xsimao.com/findings/ostium-update-pair-missing-modifier) |
| High | USDC Blacklisting Prevents Trader Liquidation | [read it](https://0xsimao.com/findings/ostium-blacklisting-prevents-trader-liquidation) |
| High | Casting from int256 to uint256 won't revert if the number is negative, possibly leading to issues | [read it](https://0xsimao.com/findings/ostium-casting-int256-won-revert) |
| Medium | utilizationThresholdP of 10_000 will make OstiumPairInfos::_getUtilizationOpeningFee() divide by 0 | [read it](https://0xsimao.com/findings/ostium-000-infos-opening-fee) |
| Medium | OstiumVault::lockDiscount() may revert due to division by 0 | [read it](https://0xsimao.com/findings/ostium-lock-discount-revert-division) |
| Medium | OstiumTradingCallbacks::executeAutomationOpenOrderCallback() reverts if it can not find the openLimitOrder | [read it](https://0xsimao.com/findings/ostium-callbacks-callback-reverts-find) |
| Medium | OstiumTrading::executeAutomationOrder() and _getLimitOrdersToTrigger() should check isPaused for open limit orders | [read it](https://0xsimao.com/findings/ostium-automation-orders-trigger-paused) |
| Medium | Missing Pausability Check in OstiumTrading::executeAutomationOrder() for Opening Orders | [read it](https://0xsimao.com/findings/ostium-pausability-automation-opening-orders) |
| Medium | OstiumTrading::topUpCollateral() is missing pairsStored.groupMaxCollateral(pairIndex) check | [read it](https://0xsimao.com/findings/ostium-collateral-pairs-stored-index) |
| Medium | OstiumTrading::closeTradeMarket() and OstiumTrading::topUpCollateral() are missing pending trigger checks | [read it](https://0xsimao.com/findings/ostium-close-trade-top-collateral) |
| Medium | Error in OstiumPairsStorage::groupMaxCollateral() calculation | [read it](https://0xsimao.com/findings/ostium-pairs-storage-group-collateral) |
| Medium | OstiumPriceUpKeep::performUpKeep() does not correctly handle possible reverts | [read it](https://0xsimao.com/findings/ostium-price-perform-correctly-reverts) |
| Medium | Trader Can Set Wrong TP and SL | [read it](https://0xsimao.com/findings/ostium-trader-set-wrong) |
| Medium | Setting maxFundingFeePerBlock to a lower value than abs(lastFundingRate) will brick getPendingAccFundingFees() | [read it](https://0xsimao.com/findings/ostium-fee-abs-brick-fees) |
| Low | OstiumTradesUpKeep Triggers Automation for Pending Orders Expected to Fail | [read it](https://0xsimao.com/findings/ostium-trades-triggers-pending-expected) |
| Low | Limitations for Users Employing Multi-sig or Account Abstraction Wallets in Setting Delegate Address | [read it](https://0xsimao.com/findings/ostium-limitations-employing-abstraction-delegate) |
| Low | executeAutomationOpenOrderCallback Executes STOP Orders at a Worse Price | [read it](https://0xsimao.com/findings/ostium-callback-executes-worse-price) |
| Low | reqID_pendingAutomationOrder stores the index of the trade, which could point to a different trade since the request was created | [read it](https://0xsimao.com/findings/ostium-req-index-point-since) |
| Low | OstiumTradingCallbacks::executeAutomationOpenOrderCallback() opens limit orders at market price instead of the limit price | [read it](https://0xsimao.com/findings/ostium-callbacks-callback-opens-price) |
| Low | OstiumPairsStorage::getAllPairsMaxLeverage() reverts if enough pairs are created | [read it](https://0xsimao.com/findings/ostium-pairs-storage-reverts-created) |
| Low | OstiumRegistry should disable renouncing ownership if it is never intended | [read it](https://0xsimao.com/findings/ostium-registry-renouncing-ownership-intended) |
| Low | OstiumLinkUpKeep:topUp() is missing a length check for registryAddresses | [read it](https://0xsimao.com/findings/ostium-link-top-registry-addresses) |
| Low | .values() may revert when calling getWatchList() due to OOG | [read it](https://0xsimao.com/findings/ostium-revert-watch-list-oog) |
| Low | In OstiumLinkUpKeep, empty watchlist or keeperIds arguments are not handled | [read it](https://0xsimao.com/findings/ostium-empty-watchlist-keeper-handled) |
| Low | Using transfer() instead of call() may revert | [read it](https://0xsimao.com/findings/ostium-transfer-instead-call-revert) |
| Low | Missing disableInitializers() call in the constructor | [read it](https://0xsimao.com/findings/ostium-disable-initializers-call-constructor) |
| Low | Ownable2Step is recommended over Ownable | [read it](https://0xsimao.com/findings/ostium-ownable2-step-recommended-ownable) |
| Info | Implement Storage Gap in Delegatable Contract | [read it](https://0xsimao.com/findings/ostium-implement-storage-gap-delegatable) |
| Info | Unused Trade Size Variable in OstiumTrading::executeAutomationOrder() | [read it](https://0xsimao.com/findings/ostium-trade-size-variable-automation) |
| Info | Implement Custom Errors Instead of require Statements | [read it](https://0xsimao.com/findings/ostium-implement-custom-require-statements) |
| Info | Inconsistent Precision of Percentage Variables | [read it](https://0xsimao.com/findings/ostium-inconsistent-precision-percentage-variables) |
| Info | Unnecessary Typecasting of msg.sender | [read it](https://0xsimao.com/findings/ostium-unnecessary-typecasting-msg-sender) |
| Info | Use of Magic Numbers | [read it](https://0xsimao.com/findings/ostium-magic-numbers) |
| Info | Unused and Wrong Imports | [read it](https://0xsimao.com/findings/ostium-unused-wrong-imports) |
| Info | Redundant Calculations in OstiumTrading::openTrade() | [read it](https://0xsimao.com/findings/ostium-redundant-calculations-trading-trade) |
| Info | OstiumTrading::closeTradeMarket() Makes Redundant Call to OstiumTradingStorage::getOpenTradeInfo() | [read it](https://0xsimao.com/findings/ostium-close-redundant-storage-info) |
| Info | OstiumLinkUpKeep Config Not Set In initialize() | [read it](https://0xsimao.com/findings/ostium-link-keep-config-initialize) |
| Info | OstiumPriceUpKeep Verifies Reports Using Native Token Instead of LINK | [read it](https://0xsimao.com/findings/ostium-price-verifies-reports-native) |
| Info | OstiumTrading::updateOpenLimitOrder() Makes Unnecessary Field Updates | [read it](https://0xsimao.com/findings/ostium-trading-unnecessary-field-updates) |
| Info | OstiumTrading::canExecute() should also be checked in OstiumTradesUpKeep::checkCallback() | [read it](https://0xsimao.com/findings/ostium-trading-checked-trades-callback) |
| Info | Unused UPDATE_SL OstiumPriceUpKeep::OrderType | [read it](https://0xsimao.com/findings/ostium-unused-price-keep-type) |
| Info | In OstiumTradesUpKeep, _getLimitOrdersToTrigger() and _getOpenOrdersToTrigger() return tradesToTrigger with 1 extra length | [read it](https://0xsimao.com/findings/ostium-trades-orders-extra-length) |
| Info | Wrong decoding of verifierResponse in OstiumPriceUpKeep::performUpkeep() | [read it](https://0xsimao.com/findings/ostium-decoding-verifier-response-price) |
| Info | updateGroupCollateral() should revert if the _pairIndex does not exist | [read it](https://0xsimao.com/findings/ostium-collateral-revert-index-exist) |
| Info | Error parameters should be more descriptive | [read it](https://0xsimao.com/findings/ostium-error-parameters-descriptive) |
| Info | Faulty revert reason decoding in Delegatable | [read it](https://0xsimao.com/findings/ostium-faulty-revert-decoding-delegatable) |
| Info | OstiumOpenPnl::average() can be simplified by adding a state variable that tracks the cumulative sum of nextEpochValues | [read it](https://0xsimao.com/findings/ostium-average-tracks-sum-epoch) |
| Info | OstiumOpenPnl::nextEpochValuesRequestCount stores the same information as nextEpochValues.length | [read it](https://0xsimao.com/findings/ostium-epoch-count-stores-information) |
| Info | Redundant abi.decode() in OstiumTradesUpKeep::checkCallback() | [read it](https://0xsimao.com/findings/ostium-redundant-abi-decode-callback) |
| Info | Consider using forceApprove instead of safeApprove in OstiumTraidingCallbacks | [read it](https://0xsimao.com/findings/ostium-force-approve-traiding-callbacks) |
| Info | OstiumLinkUpKeep:removeFromWatchList() complexity could be reduced | [read it](https://0xsimao.com/findings/ostium-watch-list-complexity-reduced) |
| Info | Typos in OstiumLinkUpKeep | [read it](https://0xsimao.com/findings/ostium-typos-ostium-link-keep) |

## Blast

Cantina · Layer 2 with native yield · 2024-01-30

[contest](https://cantina.xyz/competitions/c90131b4-5c7c-4ebc-a1f3-8002d219bfe0)

3 findings. The platform has not published this contest's findings.

## NFTPerp II

Three Sigma · NFT perpetuals · 2024-01-29

[report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-01-29-nftperp-ii.pdf)

15 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| Medium | Call _updateMarkPrice() whenever markPrice is changed | [read it](https://0xsimao.com/findings/nftperp-ii-mark-price-whenever-changed) |
| Medium | _match() always checks the trigger of the first order of a certain tick, instead of checking i order | [read it](https://0xsimao.com/findings/nftperp-ii-match-certain-tick-checking) |
| Medium | Use a flag to increase or decrease the index of the pool instead of a heuristic | [read it](https://0xsimao.com/findings/nftperp-ii-flag-decrease-index-heuristic) |
| Medium | Notional difference in AmmRouter:removeLiquidty() may revert in certain cases | [read it](https://0xsimao.com/findings/nftperp-ii-notional-difference-liquidty-revert) |
| Medium | It's possible to mint an infinite number of shares without increasing quote or base amounts, due to rounding down | [read it](https://0xsimao.com/findings/nftperp-ii-mint-infinite-shares-rounding) |
| Medium | Price deviation as is can be circumvented by making smaller trades in a loop | [read it](https://0xsimao.com/findings/nftperp-ii-price-deviation-circumvented-loop) |
| Info | PositionManager:_reversePosition() calculates the notional to reverse but could just use the exchangedQuote | [read it](https://0xsimao.com/findings/nftperp-ii-reverse-calculates-exchanged-quote) |
| Info | Duplicate size to fill check in _staticFillToAmm() | [read it](https://0xsimao.com/findings/nftperp-ii-duplicate-size-fill-static) |
| Info | gap is missing the private keyword | [read it](https://0xsimao.com/findings/nftperp-ii-gap-missing-private-keyword) |
| Info | Index underflow is not protected against, although it has no impact as the pool with index type(uint256).max should not be registered | [read it](https://0xsimao.com/findings/nftperp-ii-index-underflow-impact-registered) |
| Info | In AmmRouter:liquidateMaker(), the pools array can safely be deleted from storage | [read it](https://0xsimao.com/findings/nftperp-ii-liquidate-array-safely-storage) |
| Info | trimDuplicatePools() is very expensive, having O(n^2) complexity and could be simplified | [read it](https://0xsimao.com/findings/nftperp-ii-trim-expensive-complexity-simplified) |
| Info | Add a 0 address check on the pool when adding liquidity for greater verbosity | [read it](https://0xsimao.com/findings/nftperp-ii-add-adding-greater-verbosity) |
| Info | setPools() could use more validation | [read it](https://0xsimao.com/findings/nftperp-ii-set-pools-validation) |
| Info | Misleading error name | [read it](https://0xsimao.com/findings/nftperp-ii-misleading-error-name) |

## Trestle

Three Sigma · Modular blockchain infrastructure · 2024-01-27

Report not published.

## Metazero I

Three Sigma · Omnichain RWA tokenisation · 2024-01-27

[protocol](https://metazero.gg/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-01-27-metazero-i.pdf)

16 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | NFTs can be stolen by calling send() and receiving the nfts in another chain | [read it](https://0xsimao.com/findings/metazero-i-stolen-send-receiving-nfts) |
| High | deTokenize() is missing access control, anyone can burn other people's nfts | [read it](https://0xsimao.com/findings/metazero-i-tokenize-access-control-burn) |
| High | Send should revert if the gas limit has not been set for a destination chain (peer) | [read it](https://0xsimao.com/findings/metazero-i-revert-gas-destination-peer) |
| High | Lost nfts due to smart wallets having different addresses on different chains | [read it](https://0xsimao.com/findings/metazero-i-nfts-wallets-having-addresses) |
| Medium | mintGenesis() mints with a push pattern using _mint() which may lead to lost tokens | [read it](https://0xsimao.com/findings/metazero-i-mint-genesis-mints-push) |
| Medium | In function mint() and lzReceive(), _safeMint() is recommended over _mint(), which performs additional checks | [read it](https://0xsimao.com/findings/metazero-i-mint-recommended-performs-additional) |
| Medium | Can not mint 1000 tokens, only 999 | [read it](https://0xsimao.com/findings/metazero-i-mint-1000-tokens-999) |
| Low | Important events are missing | [read it](https://0xsimao.com/findings/metazero-i-important-events-missing) |
| Low | renounceOwnership() should be disabled if it is not intended to be ever used | [read it](https://0xsimao.com/findings/metazero-i-renounce-ownership-intended-ever) |
| Low | Ownable2Step should be preferred over Ownable | [read it](https://0xsimao.com/findings/metazero-i-ownable2-step-preferred-ownable) |
| Info | genesisMint gas costs can be reduced by caching genesisCounter | [read it](https://0xsimao.com/findings/metazero-i-mint-gas-caching-counter) |
| Info | _setDefaultRoyalty() in the constructor is overriding the BasicRoyalties constructor | [read it](https://0xsimao.com/findings/metazero-i-default-royalty-overriding-royalties) |
| Info | Unused parameters names can be removed to ignore compiler warnings | [read it](https://0xsimao.com/findings/metazero-i-names-ignore-compiler-warnings) |
| Info | Hardcoded variables should be placed as constants | [read it](https://0xsimao.com/findings/metazero-i-hardcoded-variables-placed-constants) |
| Info | genesisLimit can be placed as constant variables to save gas. | [read it](https://0xsimao.com/findings/metazero-i-genesis-placed-constant-gas) |
| Info | pragma abicoder v2; is enforced for solidity versions above 0.8.0 | [read it](https://0xsimao.com/findings/metazero-i-pragma-abicoder-enforced-versions) |

## INIT Capital I

Code4rena · Money market · 2024-01-26

[protocol](https://init.capital/) · [report](https://github.com/0xsimao/audits/blob/main/Code4rena/private-audits/2024-01-26-init-capital-i.md)

No findings.

## M^0

Three Sigma · Stablecoin framework · 2024-01-08

[protocol](https://www.m0.org/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-01-08-m-0.pdf)

32 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | Lack of deadline in PowerToken.buy can lead to user's cashToken being distributed through ZeroToken holders | [read it](https://0xsimao.com/findings/m-0-deadline-cash-through-zero) |
| High | Validator signature with zero timestamp can always be replayed | [read it](https://0xsimao.com/findings/m-0-signature-zero-timestamp-replayed) |
| High | MToken's total principal invariant can be broken | [read it](https://0xsimao.com/findings/m-0-total-principal-invariant-broken) |
| Medium | Creating a new proposal in StandardGovernor may reach a state of permanent DoS | [read it](https://0xsimao.com/findings/m-0-creating-proposal-reach-permanent) |
| Medium | A sufficiently large collateral may break the maximum owed M calculation | [read it](https://0xsimao.com/findings/m-0-sufficiently-collateral-maximum-owed) |
| Medium | Validator signatures with greater timestamps can be reused in a subsequent updateCollateral | [read it](https://0xsimao.com/findings/m-0-greater-timestamps-subsequent-collateral) |
| Low | Multiplication after division in StableEarnerRateModel leads to loss of precision | [read it](https://0xsimao.com/findings/m-0-stable-earner-model-precision) |
| Low | A decrease in updateCollateralInterval will lead to unfair penalties | [read it](https://0xsimao.com/findings/m-0-collateral-interval-unfair-penalties) |
| Low | Unhandled rounding error in DistributionVault.getClaimable leads to locked dust | [read it](https://0xsimao.com/findings/m-0-rounding-claimable-locked-dust) |
| Low | MToken's total principal invariant doesn't hold without MinterGateway, leading to potential principal loss | [read it](https://0xsimao.com/findings/m-0-invariant-hold-minter-gateway) |
| Low | Unrealized inflation calculation returns wrong value when balance reaches cap | [read it](https://0xsimao.com/findings/m-0-unrealized-inflation-returns-reaches) |
| Low | Custom error for overflowing the total principal is not raised | [read it](https://0xsimao.com/findings/m-0-custom-overflowing-principal-raised) |
| Low | Proposals in the same voting period can have different ids but do the same | [read it](https://0xsimao.com/findings/m-0-proposals-voting-period-ids) |
| Low | Function cancelMint can be frontrunned to grief a validator | [read it](https://0xsimao.com/findings/m-0-mint-frontrunned-grief-validator) |
| Low | StandardGovernor's implementation of quorum is incompatible with Tally | [read it](https://0xsimao.com/findings/m-0-implementation-quorum-incompatible-tally) |
| Info | Missing override keyword for interface inherited methods | [read it](https://0xsimao.com/findings/m-0-override-keyword-inherited-methods) |
| Info | Some contracts don't implement their entire interface | [read it](https://0xsimao.com/findings/m-0-don-implement-entire-interface) |
| Info | No need to set isActive to false if that mapping entry was deleted | [read it](https://0xsimao.com/findings/m-0-active-mapping-entry-deleted) |
| Info | Unnecessary Recomputation of Storage Pointer in MToken._startEarning | [read it](https://0xsimao.com/findings/m-0-recomputation-storage-pointer-earning) |
| Info | Unnecessary check in StandardGovernor.state | [read it](https://0xsimao.com/findings/m-0-unnecessary-standard-governor-state) |
| Info | Code should not panic underflow | [read it](https://0xsimao.com/findings/m-0-code-panic-underflow) |
| Info | StartedEarning event is emitted even if account is already earning | [read it](https://0xsimao.com/findings/m-0-started-earning-emitted-already) |
| Info | Wrong comment in Standard Governor's execute function | [read it](https://0xsimao.com/findings/m-0-comment-standard-governor-function) |
| Info | Unnecessary currentEpoch zero check in StandardGovernor and ThresholdGovernor | [read it](https://0xsimao.com/findings/m-0-current-epoch-zero-threshold) |
| Info | Overflow check in PowerToken._divideUp is unnecessary | [read it](https://0xsimao.com/findings/m-0-overflow-power-divide-unnecessary) |
| Info | Unnecessary conditional check in ThresholdGovernance.execute | [read it](https://0xsimao.com/findings/m-0-unnecessary-conditional-threshold-governance) |
| Info | Inconsistent naming of function in PureEpochs | [read it](https://0xsimao.com/findings/m-0-inconsistent-naming-pure-epochs) |
| Info | _checkAndIncrementNonce in ERC5805 raises a ReusedNonce error for non used nonces | [read it](https://0xsimao.com/findings/m-0-nonce-erc5805-raises-nonces) |
| Info | castVoteWithReason always fires a VoteCast event with an empty reason | [read it](https://0xsimao.com/findings/m-0-cast-vote-reason-fires) |
| Info | transferFrom in ERC20Extended will always emit an Approval event if the allowance changes | [read it](https://0xsimao.com/findings/m-0-transfer-erc20-approval-allowance) |
| Info | EIP712's _revertIfError should use all SignatureChecker.Error errors | [read it](https://0xsimao.com/findings/m-0-eip712-revert-signature-checker) |
| Info | The IERC3009 interface is not fully conforming to the standard | [read it](https://0xsimao.com/findings/m-0-ierc3009-interface-fully-conforming) |

## NftPerp I

Three Sigma · NFT perpetuals · 2024-01-02

[report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2024-01-02-nftperp-i.pdf)

20 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | reduceOnly limit order update does not take into account that a new amm may be selected, which may lead to loss of funds | [read it](https://0xsimao.com/findings/nftperp-i-reduce-account-amm-selected) |
| High | Realized pnl not returned to trader on _mergeDecrease() | [read it](https://0xsimao.com/findings/nftperp-i-realized-returned-trader-merge) |
| Medium | _getPositionNotional() crops the size of the position to the available reserves, which may lead to unexpected profits/losses | [read it](https://0xsimao.com/findings/nftperp-i-notional-crops-unexpected-profits) |
| Medium | Partially removing liquidity may underflow if the price of the pool has changed significantly | [read it](https://0xsimao.com/findings/nftperp-i-partially-underflow-price-significantly) |
| Medium | removeLiquidity() in the amm calculates marginToRemove without updating the margin with the funding payment | [read it](https://0xsimao.com/findings/nftperp-i-calculates-margin-updating-payment) |
| Medium | _getPriceToTick() reverts if the price is smaller than 1e10, which may happen in _search() as it assumes the final tick as going entirely to the amm | [read it](https://0xsimao.com/findings/nftperp-i-price-reverts-happen-entirely) |
| Medium | setFundingPeriod() can be DoSed due to calling settleFunding() | [read it](https://0xsimao.com/findings/nftperp-i-funding-period-calling-settle) |
| Low | In fillPair(), when the taker is the maker, the reduceOnly order mapping is not being deleted | [read it](https://0xsimao.com/findings/nftperp-i-fill-taker-maker-deleted) |
| Low | getTriggerOrders() should be paginated or it may revert if enough orders are created | [read it](https://0xsimao.com/findings/nftperp-i-orders-paginated-revert-created) |
| Low | PriceFeed: Two step owner transfers are safer | [read it](https://0xsimao.com/findings/nftperp-i-price-two-transfers-safer) |
| Low | Total Position Size isn't updated properly | [read it](https://0xsimao.com/findings/nftperp-i-size-isn-updated-properly) |
| Info | State changes should always emit events | [read it](https://0xsimao.com/findings/nftperp-i-state-changes-emit-events) |
| Info | Swapping amounts that would send the price below/above the bounds of the amm underflows without a reason | [read it](https://0xsimao.com/findings/nftperp-i-price-below-bounds-underflows) |
| Info | PriceFeed: First owner isn't set as valid keeper | [read it](https://0xsimao.com/findings/nftperp-i-price-isn-valid-keeper) |
| Info | Structs can be packed to save gas | [read it](https://0xsimao.com/findings/nftperp-i-structs-packed-save-gas) |
| Info | Contracts should inherit their interfaces | [read it](https://0xsimao.com/findings/nftperp-i-contracts-inherit-their-interfaces) |
| Info | Bug in _reversePosition() might lead to future exploits | [read it](https://0xsimao.com/findings/nftperp-i-bug-reverse-future-exploits) |
| Info | Using low level pop is not recommended | [read it](https://0xsimao.com/findings/nftperp-i-low-level-pop-recommended) |
| Info | Errors could include relevant arguments whenever possible, making it easier to debug | [read it](https://0xsimao.com/findings/nftperp-i-include-relevant-easier-debug) |
| Info | mul() and div() in NFTPMath are misleading due to scaling by 1e18 underneath | [read it](https://0xsimao.com/findings/nftperp-i-nftp-scaling-1e18-underneath) |

## INIT Capital II

Code4rena · Money market · 2023-12-15

[protocol](https://init.capital/) · [report](https://github.com/0xsimao/audits/blob/main/Code4rena/private-audits/2023-12-15-init-capital-ii.md)

5 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Liquidations can be prevented by frontrunning and liquidating 1 debt (or more) due to wrong assumption in POS_MANAGER | [read it](https://0xsimao.com/findings/init-capital-ii-liquidations-frontrunning-debt-assumption) |
| Medium | repay(), liquidate() and liquidateWLp() receive shares as argument, which may revert if from approval to tx settled blocks have passed | [read it](https://0xsimao.com/findings/init-capital-ii-repay-liquidate-shares-approval) |
| Medium | Decimals of LendingPool don't take into account the offset introduced by VIRTUAL_SHARES | [read it](https://0xsimao.com/findings/init-capital-ii-decimals-introduced-virtual-shares) |
| Medium | If wLP is blacklisted, then user will not be able to withdraw it | [read it](https://0xsimao.com/findings/init-capital-ii-blacklisted-user-able-withdraw) |
| Medium | API3 oracle timestamp can be set to future timestamp and block API3 Oracle usage to make code revert in underflow | [read it](https://0xsimao.com/findings/init-capital-ii-oracle-timestamp-revert-underflow) |

## Maple Finance II

Three Sigma · Institutional lending · 2023-11-16

[protocol](https://maple.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2023-11-16-maple-finance-ii.pdf)

7 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| Low | Queue MapleWithdrawalManager may revert due to honest removeShares() or manual redeem calls | [read it](https://0xsimao.com/findings/maple-finance-ii-queue-withdrawal-shares-redeem) |
| Low | Unbounded loops in MapleWithdrawalManager may break in the future if the withdrawal windows are small | [read it](https://0xsimao.com/findings/maple-finance-ii-unbounded-loops-withdrawal-windows) |
| Low | Factory update for maple loans can be performed with the old factory | [read it](https://0xsimao.com/findings/maple-finance-ii-factory-loans-performed-old) |
| Info | Allow lenders to set a minimum amount of asset they would take for their shares | [read it](https://0xsimao.com/findings/maple-finance-ii-lenders-minimum-they-shares) |
| Info | Gas savings | [read it](https://0xsimao.com/findings/maple-finance-ii-gas-savings) |
| Info | Operational Admin Suggestions | [read it](https://0xsimao.com/findings/maple-finance-ii-operational-admin-suggestions) |
| Info | Documentation inconsistencies | [read it](https://0xsimao.com/findings/maple-finance-ii-documentation-inconsistencies) |

## Clip Finance I

Three Sigma · DeFi infrastructure · 2023-11-10

[protocol](https://www.clip.finance/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2023-11-10-clip-finance-i.pdf)

17 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | Anyone can grief users, stopping them from fulfilling their withdrawals | [read it](https://0xsimao.com/findings/clip-finance-i-grief-stopping-fulfilling-withdrawals) |
| High | Swapping with deadline as block.timestamp and 0 minimum amount out is vulnerable to MEV | [read it](https://0xsimao.com/findings/clip-finance-i-swapping-deadline-timestamp-mev) |
| High | BatchOut:executeBatchWithdrawFromStrategyWithSwap() gives unfairly different slippage depending on the chosen token | [read it](https://0xsimao.com/findings/clip-finance-i-withdraw-unfairly-slippage-depending) |
| High | BatchOut:withdrawFulfill() can be DoSed by spamming withdrawal requests, leading to OOG reverts | [read it](https://0xsimao.com/findings/clip-finance-i-withdraw-spamming-withdrawal-reverts) |
| High | Scheduled withdrawals with unsupported tokens will be halted | [read it](https://0xsimao.com/findings/clip-finance-i-scheduled-withdrawals-unsupported-halted) |
| High | Halted withdrawals in BatchOut due to setting withdrawTo to address(0) in scheduleWithdrawal() | [read it](https://0xsimao.com/findings/clip-finance-i-withdrawals-withdraw-schedule-withdrawal) |
| High | Yield loss due to StrategyRouterLib:rebalanceStrategies() not allocating saturated strategy deposits | [read it](https://0xsimao.com/findings/clip-finance-i-yield-allocating-saturated-deposits) |
| High | Halted withdrawals in BatchOut:withdrawFulfill() due to tokens transfer() reverting on 0 transfer amount | [read it](https://0xsimao.com/findings/clip-finance-i-halted-withdrawals-withdraw-transfer) |
| High | Inconsistent batch:rebalance() behavior when some strategies reach their limit, leading to yield loss | [read it](https://0xsimao.com/findings/clip-finance-i-inconsistent-behavior-reach-yield) |
| High | Tokens with callbacks may allow malicious attackers to steal the protocol | [read it](https://0xsimao.com/findings/clip-finance-i-callbacks-malicious-attackers-steal) |
| Medium | Potential overflow in PancakeSwapPlugin:getRoutePrice() | [read it](https://0xsimao.com/findings/clip-finance-i-overflow-pancake-plugin-price) |
| Medium | DoSed StrategyRouter:withdrawFromStrategies() if strategyTokenBalancesUsd[i] is too small in the swapping phase | [read it](https://0xsimao.com/findings/clip-finance-i-withdraw-balances-usd-phase) |
| Medium | Batch:withdraw() can be DoSed by frontrunning it with strategyRouter:allocateToStrategies() | [read it](https://0xsimao.com/findings/clip-finance-i-withdraw-frontrunning-allocate-strategies) |
| Medium | StrategyRouterLib.sol bug when subtracting from balance | [read it](https://0xsimao.com/findings/clip-finance-i-lib-sol-bug-subtracting) |
| Medium | Fee on transfer tokens transfer less tokens than what is stored in the receipt on deposits | [read it](https://0xsimao.com/findings/clip-finance-i-fee-transfer-receipt-deposits) |
| Low | Missing fee refund on Batch.sol | [read it](https://0xsimao.com/findings/clip-finance-i-fee-refund-batch-sol) |
| Low | getDepositFeeInBNB() assumes a stablecoin price of 1 USD, which may not be true if it depegs | [read it](https://0xsimao.com/findings/clip-finance-i-deposit-fee-price-depegs) |

## Chainlink Staking v0.2

Code4rena · Oracle staking · 2023-08-25

[contest](https://code4rena.com/audits/2023-08-chainlink-staking-v02)

No findings.

## veRWA

Code4rena · Voting-escrow gauges · 2023-08-07

[contest](https://code4rena.com/audits/2023-08-verwa)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Voters from VotingEscrow can vote infinite times in vote_for_gauge_weights() of GaugeController | [read it](https://0xsimao.com/findings/verwa-voters-voting-escrow-vote) |

## Perennial V2

Sherlock · Perpetuals and derivatives · 2023-07-24

[contest](https://audits.sherlock.xyz/contests/106)

2 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Protocol fee from Market.sol is locked | [read it](https://0xsimao.com/findings/perennial-v2-fee-market-sol-locked) |
| Medium | Drained oracle fees from market by depositing and withdrawing immediately without triggering settlement fees | [read it](https://0xsimao.com/findings/perennial-v2-oracle-fees-triggering-settlement) |

## Tokemak

Sherlock · Liquidity provisioning · 2023-07-17

[contest](https://audits.sherlock.xyz/contests/101)

7 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Immediately start getting rewards belonging to others after staking | [read it](https://0xsimao.com/findings/tokemak-rewards-belonging-others-staking) |
| High | Aura/Convex rewards are stuck after DOS | [read it](https://0xsimao.com/findings/tokemak-convex-rewards-stuck-dos) |
| High | Destination Vault rewards are not added to idleIncrease when info.totalAssetsPulled > info.totalAssetsToPull | [read it](https://0xsimao.com/findings/tokemak-rewards-info-pulled-pull) |
| High | Liquidations miss delegate call to swapper | [read it](https://0xsimao.com/findings/tokemak-liquidations-miss-delegate-swapper) |
| Medium | Lost rewards when the supply is `0`, which always happens if the rewards are queued before anyone has `StakeTracker` tokens | [read it](https://0xsimao.com/findings/tokemak-rewards-happens-stake-tracker) |
| Medium | `previewRedeem` and `redeem` functions deviate from the ERC4626 specification | [read it](https://0xsimao.com/findings/tokemak-redeem-deviate-erc4626-specification) |
| Medium | Malicious users could lock in the NAV/Share of the DV to cause the loss of fees | [read it](https://0xsimao.com/findings/tokemak-lock-nav-share-fees) |

## Glacier

Three Sigma · Liquid staking · 2023-07-12

[protocol](https://www.glacier.io/) · [report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2023-07-12-glacier.pdf)

32 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | AaveV3 RewardsController provides rewards in any token, should be handled separately | [read it](https://0xsimao.com/findings/glacier-aave-rewards-provides-separately) |
| High | totalReserves should be fetched from the strategies individually and summed up in the ReservePool | [read it](https://0xsimao.com/findings/glacier-reserves-fetched-individually-summed) |
| High | increaseNetworkTotal() allows big arbitrage opportunities by depositing before an increase transaction | [read it](https://0xsimao.com/findings/glacier-network-big-opportunities-transaction) |
| High | _rebalanceWithdraw() mechanism in glAVAX allows arbitrage opportunities by changing the shares/AVAX ratio | [read it](https://0xsimao.com/findings/glacier-withdraw-arbitrage-opportunities-shares) |
| High | In glAVAX, function _rebalanceWithdraw() withdraws incorrect amount from WAVAX address | [read it](https://0xsimao.com/findings/glacier-rebalance-withdraw-withdraws-wavax) |
| High | In GReservePool, if a strategy is frozen reserve pool stops working | [read it](https://0xsimao.com/findings/glacier-reserve-frozen-stops-working) |
| Medium | When changing addresses, use 2 step transfer and/or address 0x0 checks | [read it](https://0xsimao.com/findings/glacier-changing-addresses-transfer-0x0) |
| Medium | Strategy withdraw may fail if weights of strategies differ from the real values and might lead to frozen ReservePool | [read it](https://0xsimao.com/findings/glacier-withdraw-weights-differ-real) |
| Medium | Withdraw snapshot logic can be tricked allowing users to withdraw right away | [read it](https://0xsimao.com/findings/glacier-withdraw-snapshot-tricked-away) |
| Low | In glAVAX, should use .call instead of .transfer | [read it](https://0xsimao.com/findings/glacier-avax-call-instead-transfer) |
| Low | Strategy percentages will differ over time as yield accrued differs in ReservePool | [read it](https://0xsimao.com/findings/glacier-percentages-differ-yield-differs) |
| Low | rebalance() in glAVAX reverts if currentReserves == reserveTarget | [read it](https://0xsimao.com/findings/glacier-reverts-current-reserves-target) |
| Low | receive() in glAVAX should only allow wAVAX | [read it](https://0xsimao.com/findings/glacier-receive-avax) |
| Info | Usage of transferFrom() could revert if used from itself | [read it](https://0xsimao.com/findings/glacier-usage-transfer-revert-itself) |
| Info | Strategies in the ReservePool could be implemented as an array and Strategy packed | [read it](https://0xsimao.com/findings/glacier-strategies-implemented-array-packed) |
| Info | Implement _transferShares() to prevent having to convert shares/wAVAX twice in glAVAX | [read it](https://0xsimao.com/findings/glacier-transfer-shares-convert-twice) |
| Info | rebalance(), withdrawAmount needed from the ReservePool can be simplified | [read it](https://0xsimao.com/findings/glacier-rebalance-withdraw-needed-simplified) |
| Info | Checks effects interactions pattern should always be used | [read it](https://0xsimao.com/findings/glacier-checks-effects-interactions-pattern) |
| Info | If statements can be inverted to increase readability | [read it](https://0xsimao.com/findings/glacier-statements-inverted-increase-readability) |
| Info | avaxAmount is never 0 in withdraw() in the first if (avaxAmount > 0 && ...) | [read it](https://0xsimao.com/findings/glacier-avax-amount-withdraw-first) |
| Info | Withdraw requests could be stored in a simpler way in glAVAX | [read it](https://0xsimao.com/findings/glacier-withdraw-stored-simpler-way) |
| Info | In glAVAX, checking that amount > 0 earlier can save some gas | [read it](https://0xsimao.com/findings/glacier-avax-checking-earlier-gas) |
| Info | In glAVAX, naming convention for storage variable should be consistent | [read it](https://0xsimao.com/findings/glacier-naming-convention-storage-consistent) |
| Info | Storage variables should be cached whenever possible to save gas | [read it](https://0xsimao.com/findings/glacier-storage-cached-whenever-gas) |
| Info | Unnecessary user balance check in _withdrawRequest() | [read it](https://0xsimao.com/findings/glacier-unnecessary-balance-withdraw-request) |
| Info | Typo in fufillWithdrawal() in glAVAX, should be fulfillWithdrawal | [read it](https://0xsimao.com/findings/glacier-typo-fufill-withdrawal-fulfill) |
| Info | In GReservePool, remove unnecessary logic | [read it](https://0xsimao.com/findings/glacier-reserve-remove-unnecessary-logic) |
| Info | In GReservePool, use constants naming conventions | [read it](https://0xsimao.com/findings/glacier-reserve-constants-naming-conventions) |
| Info | In GLendingPool, remove incorrect comment | [read it](https://0xsimao.com/findings/glacier-lending-remove-incorrect-comment) |
| Info | In GLendingPool, event parameters can be indexed | [read it](https://0xsimao.com/findings/glacier-lending-event-parameters-indexed) |
| Info | Remove unused imports | [read it](https://0xsimao.com/findings/glacier-remove-unused-imports) |
| Info | NatSpect comments should include explanations of parameters and return variables | [read it](https://0xsimao.com/findings/glacier-nat-spect-comments-explanations) |

## Tapioca DAO

Code4rena · Omnichain money market · 2023-07-05

[contest](https://code4rena.com/audits/2023-07-tapioca-dao)

10 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | TOFT in (m)TapiocaOft contracts can be stolen by calling removeCollateral() with a malicious removeParams.market | [read it](https://0xsimao.com/findings/tapioca-dao-toft-stolen-collateral-params) |
| High | TOFT `removeCollateral` can be used to steal all the balance | [read it](https://0xsimao.com/findings/tapioca-dao-toft-remove-collateral-steal) |
| High | All assets of (m)TapiocaOFT can be stealed by depositing to strategy cross chain call with 1 amount but maximum shares possible | [read it](https://0xsimao.com/findings/tapioca-dao-tapioca-stealed-maximum-shares) |
| High | Attacker can block LayerZero channel due to missing check of minimum gas passed | [read it](https://0xsimao.com/findings/tapioca-dao-layer-zero-channel-gas) |
| High | TOFT and USDO Modules Can Be Selfdestructed | [read it](https://0xsimao.com/findings/tapioca-dao-toft-usdo-modules-selfdestructed) |
| High | Exercise option cross chain message in the (m)TapiocaOFT will always revert in the destination, losing debited funds in the source chain | [read it](https://0xsimao.com/findings/tapioca-dao-exercise-revert-losing-debited) |
| High | `BaseTOFT.sol`: `retrieveFromStrategy` can be used to manipulate other user's positions due to absent approval check | [read it](https://0xsimao.com/findings/tapioca-dao-retrieve-manipulate-absent-approval) |
| High | triggerSendFrom() will send all the ETH in the destination chain where sendFrom() is called to the refundAddress in the LzCallParams argument | [read it](https://0xsimao.com/findings/tapioca-dao-eth-refund-params-argument) |
| High | A user with a TapiocaOFT allowance >0 could steal all the underlying ERC20 tokens of the owner | [read it](https://0xsimao.com/findings/tapioca-dao-allowance-steal-underlying-erc20) |
| Medium | mTapiocaOFT can't be rebalanced because the Balancer in tapiocaz-audit calls swapETH() or swap() of the RouterETH but does not forward ether for the message fee | [read it](https://0xsimao.com/findings/tapioca-dao-rebalanced-balancer-eth-fee) |

## BASE

Code4rena · Ethereum layer 2 · 2023-05-26

[contest](https://code4rena.com/audits/2023-05-base)

No findings.

## Venus Protocol Isolated Pools

Code4rena · Isolated lending markets · 2023-05-08

[contest](https://code4rena.com/audits/2023-05-venus-protocol-isolated-pools)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | It's possible to borrow, redeem, transfer tokens and exit markets with outdated collateral prices and borrow interest | [read it](https://0xsimao.com/findings/venus-protocol-isolated-pools-borrow-redeem-collateral-interest) |

## Fuji Finance

Three Sigma · Lending aggregator · 2023-05-06

[report](https://github.com/0xsimao/audits/blob/main/Three%20Sigma/2023-05-06-fuji-finance.pdf)

46 findings — the review's, as the report lists them

| Severity | Finding | Read it |
|---|---|---|
| High | In BaseRouter, the beneficiary isn't checked when starting a flashloan action and it replaces the previous beneficiary | [read it](https://0xsimao.com/findings/fuji-finance-beneficiary-starting-flashloan-replaces) |
| High | Wrong tokensToCheck logic in BaseRouter enables attackers to steal funds | [read it](https://0xsimao.com/findings/fuji-finance-logic-enables-attackers-steal) |
| High | Changing providers might lead to lost assets in BorrowingVault and YieldVault | [read it](https://0xsimao.com/findings/fuji-finance-changing-providers-lost-yield) |
| High | REBALANCER_ROLE can drain funds by rebalancing in a loop in the BorrowingVault | [read it](https://0xsimao.com/findings/fuji-finance-rebalancer-drain-rebalancing-loop) |
| High | UniswapV2Swapper uses block.timestamp for deadline [Out of scope] | [read it](https://0xsimao.com/findings/fuji-finance-uniswap-timestamp-deadline-scope) |
| High | ConnextHandler executeFailedWithUpdatedArgs(...) reentrancy allowedCaller can steal all ConnextHandler tokens | [read it](https://0xsimao.com/findings/fuji-finance-handler-reentrancy-caller-steal) |
| High | Wrong transformation in function previewMintDebt(...) | [read it](https://0xsimao.com/findings/fuji-finance-transformation-preview-mint-debt) |
| High | safeApprove(...) reverts if approval is different than 0, use safeIncreaseAllowance(...) instead | [read it](https://0xsimao.com/findings/fuji-finance-approve-reverts-approval-allowance) |
| High | Attackers can claim deposits to vaults if users specify the router as receiver and don't withdraw shares after | [read it](https://0xsimao.com/findings/fuji-finance-deposits-specify-withdraw-shares) |
| High | BorrowingVault, if the debt/assets ratio falls too much, liquidators could choose to repay debt equal to the assets at a discount | [read it](https://0xsimao.com/findings/fuji-finance-debt-falls-choose-repay) |
| High | ConnextRouter fails to record failed message if gas sent is not enough | [read it](https://0xsimao.com/findings/fuji-finance-fails-record-message-gas) |
| High | Users can claim tokens in ConnextRouter by calling xReceive(...) directly | [read it](https://0xsimao.com/findings/fuji-finance-claim-connext-calling-directly) |
| Medium | Payback can be DoSed in the BorrowingVault, may be profitable for liquidators | [read it](https://0xsimao.com/findings/fuji-finance-payback-borrowing-profitable-liquidators) |
| Medium | Approval in BaseVault reduces over time | [read it](https://0xsimao.com/findings/fuji-finance-approval-base-reduces-time) |
| Medium | BaseFlasher transfers tokens and then calls xBundle(...), so the sent tokens can't be returned due to the balance check | [read it](https://0xsimao.com/findings/fuji-finance-flasher-transfers-bundle-returned) |
| Medium | _crossTransfer(...) reverts for smart contracts that don't share the same address on different chains | [read it](https://0xsimao.com/findings/fuji-finance-cross-transfer-reverts-share) |
| Medium | It's impossible to do a depositETH action on xReceive(...) in ConnextRouter | [read it](https://0xsimao.com/findings/fuji-finance-impossible-deposit-eth-action) |
| Medium | Connext delegates can perform important actions, make sure smart contract users implement them | [read it](https://0xsimao.com/findings/fuji-finance-perform-important-actions-sure) |
| Medium | Withdraw and borrow can be DoSed in BaseRouter | [read it](https://0xsimao.com/findings/fuji-finance-withdraw-borrow-sed-base) |
| Low | Handling someone else repaying debt for the BorrowingVault could be done differently | [read it](https://0xsimao.com/findings/fuji-finance-handling-someone-debt-differently) |
| Low | BaseVault is not fully ERC5143 compliant | [read it](https://0xsimao.com/findings/fuji-finance-base-fully-erc5143-compliant) |
| Low | In BaseRouter, _handleSwapAction(...), users shouldn't be allowed to send funds to an allowed flasher | [read it](https://0xsimao.com/findings/fuji-finance-handle-action-shouldn-flasher) |
| Low | BaseRouter, _bundleInternal(...) Action.Flashloan does not check if the selector matches xBundle(...) | [read it](https://0xsimao.com/findings/fuji-finance-bundle-internal-flashloan-matches) |
| Low | _crossTransfer(...) should revert if users specify routerByDomain[destDomain] as destination | [read it](https://0xsimao.com/findings/fuji-finance-transfer-revert-specify-dest) |
| Low | executeFailedWithUpdatedArgs(...) shouldn't be able to change beneficiary | [read it](https://0xsimao.com/findings/fuji-finance-args-shouldn-change-beneficiary) |
| Low | When changing addresses, use 2 step transfer and/or contract size and/or address 0x0 checks | [read it](https://0xsimao.com/findings/fuji-finance-changing-addresses-transfer-0x0) |
| Low | _getBeneficiaryFromCalldata(...) in ConnextRouter should not allow the first action to be depositETH(...) | [read it](https://0xsimao.com/findings/fuji-finance-beneficiary-calldata-deposit-eth) |
| Info | Borrowing is not vulnerable to an inflation attack, it's unnecessary to borrow when initializing the vault | [read it](https://0xsimao.com/findings/fuji-finance-inflation-attack-borrow-initializing) |
| Info | YieldVault maxRedeem(...) unnecessarily converts shares to assets and back to shares again | [read it](https://0xsimao.com/findings/fuji-finance-yield-redeem-converts-shares) |
| Info | Throughout code base, implement using SafeERC20 for IERC20 for better readability | [read it](https://0xsimao.com/findings/fuji-finance-erc20-ierc20-better-readability) |
| Info | BaseFlasher does extra abi.encode unnecessarily | [read it](https://0xsimao.com/findings/fuji-finance-flasher-abi-encode-unnecessarily) |
| Info | ConnextHandler can store the hash of the failed messages instead | [read it](https://0xsimao.com/findings/fuji-finance-handler-store-hash-messages) |
| Info | When recording failed transactions in ConnextHandler, getting the next Nonce involves an unnecessary for loop | [read it](https://0xsimao.com/findings/fuji-finance-recording-transactions-nonce-loop) |
| Info | Mismatching calldata in _crossTransferWithCalldata(...) and xReceive(...) in ConnextRouter | [read it](https://0xsimao.com/findings/fuji-finance-mismatching-calldata-cross-transfer) |
| Info | In ConnextHandler, executeFailedWithUpdatedArgs(...), the whole tx is updated on storage if the try call succeeds | [read it](https://0xsimao.com/findings/fuji-finance-whole-storage-try-succeeds) |
| Info | When transferring tokens, if the amount is 0, the transfer should be skipped | [read it](https://0xsimao.com/findings/fuji-finance-transferring-amount-transfer-skipped) |
| Info | xBundle(...) and xReceive(...) should have nonReentrant modifiers | [read it](https://0xsimao.com/findings/fuji-finance-bundle-non-reentrant-modifiers) |
| Info | _to argument missing 0x0 address check in the ConnextRouter | [read it](https://0xsimao.com/findings/fuji-finance-argument-0x0-address-connext) |
| Info | _checkNoBalanceChange(...) cycle should break in BaseRouter | [read it](https://0xsimao.com/findings/fuji-finance-balance-change-cycle-break) |
| Info | _handleSwapAction(...) creates situations where the arguments receiver and sweeper need to be the same address in BaseRouter | [read it](https://0xsimao.com/findings/fuji-finance-handle-creates-situations-sweeper) |
| Info | Constants should be placed as constants and not hardcoded for better readability | [read it](https://0xsimao.com/findings/fuji-finance-constants-hardcoded-better-readability) |
| Info | _tempTokenToCheck in BaseRouter does not need to be a state variable | [read it](https://0xsimao.com/findings/fuji-finance-temp-need-state-variable) |
| Info | Unnecessary extra condition in if statement | [read it](https://0xsimao.com/findings/fuji-finance-unnecessary-extra-condition-statement) |
| Info | Useless else statement | [read it](https://0xsimao.com/findings/fuji-finance-useless-else-statement) |
| Info | Saving parameters in memory without using them spends gas | [read it](https://0xsimao.com/findings/fuji-finance-saving-memory-spends-gas) |
| Info | Don't return the same memory variable if your passing it as argument | [read it](https://0xsimao.com/findings/fuji-finance-memory-your-passing-argument) |

## Ajna Protocol

Code4rena · Oracleless lending · 2023-05-03

[contest](https://code4rena.com/audits/2023-05-ajna-protocol)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Delegate rewards system is unfair to delegates with less tokens and reduces decentralization | [read it](https://0xsimao.com/findings/ajna-protocol-delegate-rewards-system-decentralization) |

## ENS

Code4rena · Ethereum Name Service · 2023-04-14

[contest](https://code4rena.com/audits/2023-04-ens-contest)

No findings.

## Frankencoin

Code4rena · CHF stablecoin · 2023-04-12

[contest](https://code4rena.com/audits/2023-04-frankencoin)

No findings.

## zkSync Era System Contracts

Code4rena · zk-rollup system contracts · 2023-03-10

[contest](https://code4rena.com/audits/2023-03-zksync-era-system-contracts-contest)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Time-sensitive contracts deployed on zkSync | [read it](https://0xsimao.com/findings/zksync-era-system-contracts-sensitive-contracts-deployed-sync) |

## Wenwin

Code4rena · On-chain lottery · 2023-03-06

[contest](https://code4rena.com/audits/2023-03-wenwin-contest)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Possibility to steal jackpot bypassing restrictions in the `executeDraw()` | [read it](https://0xsimao.com/findings/wenwin-possibility-steal-jackpot-bypassing) |

## Ethos Reserve

Code4rena · CDP stablecoin · 2023-02-16

[contest](https://code4rena.com/audits/2023-02-ethos-reserve-contest)

No findings.

## Biconomy

Code4rena · Smart accounts · 2023-01-04

[contest](https://code4rena.com/audits/2023-01-biconomy-smart-contract-wallet-contest)

1 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| High | Attacker can gain control of counterfactual wallet | [read it](https://0xsimao.com/findings/biconomy-gain-control-counterfactual-wallet) |

## GoGoPool

Code4rena · Avalanche liquid staking · 2022-12-15

[contest](https://code4rena.com/audits/2022-12-gogopool-contest)

3 findings — credited to 0x73696d616f

| Severity | Finding | Read it |
|---|---|---|
| Medium | Slashing fails when node operator doesn't have enough staked `GGP` | [read it](https://0xsimao.com/findings/gogopool-slashing-fails-node-ggp) |
| Medium | Any duration can be passed by node operator | [read it](https://0xsimao.com/findings/gogopool-duration-passed-node-operator) |
| Medium | Wrong reward distribution between early and late depositors because of the late `syncRewards()` call in the cycle, `syncReward()` logic should be executed in each withdraw or deposits (without reverting) | [read it](https://0xsimao.com/findings/gogopool-reward-rewards-withdraw-deposits) |
