This repository has been archived by the owner on Jan 12, 2025. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 6
Issues: sherlock-audit/2024-06-magicsea-judging
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
ZanyBonzy - Lack of support for fee on transfer, rebasing and tokens with balance modifications outside of transfers.
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Won't Fix
#545
opened Jul 15, 2024 by
sherlock-admin3
iamnmt - Unclaimed rewards when emergency withdrawing are not redistributed in This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
MasterChef
and MlumStaking
Escalation Resolved
#460
opened Jul 15, 2024 by
sherlock-admin2
Yashar - Attacker can manipulate the A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
lockDuration
of other users positions
Has Duplicates
#378
opened Jul 15, 2024 by
sherlock-admin4
minhquanym - Inconsistent check in A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
harvestPositionsTo()
function
Has Duplicates
#329
opened Jul 15, 2024 by
sherlock-admin3
ChinmayF - Voting and bribe rewards can be hijacked during emergency unlock by already existing positions
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#290
opened Jul 15, 2024 by
sherlock-admin4
santipu_ - Attacker can block all votes to a specific pool by triggering an overflow error
Escalation Resolved
This issue's escalations have been approved/rejected
High
A High severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#237
opened Jul 15, 2024 by
sherlock-admin2
BlockBusters - Rewards might get stuck when approved actor renews a position
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#207
opened Jul 15, 2024 by
sherlock-admin2
dimulski - Adding genuine BribeRewarder contract instances to a pool in order to incentivize users can be DOSed
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#190
opened Jul 15, 2024 by
sherlock-admin3
ChinmayF - Funds unutilized for rewards may get stranded in BribeRewarder
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#172
opened Jul 15, 2024 by
sherlock-admin3
cocacola - Voting does not take into account end of staking lock period
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#166
opened Jul 15, 2024 by
sherlock-admin3
ChinmayF - Voters will lose all bribe rewards forever if they do not claim their rewards after the last bribing period
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#164
opened Jul 15, 2024 by
sherlock-admin4
robertodf - A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
MlumStaking::addToPosition
should assing the amount multiplier based on the new lock duration instead of initial lock duration.
Has Duplicates
#138
opened Jul 15, 2024 by
sherlock-admin2
PUSH0 - Wrong call order for A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
setTopPoolIdsWithWeights
, resulting in wrong distribution of rewards
Has Duplicates
#107
opened Jul 15, 2024 by
sherlock-admin4
PUSH0 - New staking positions still gets the full reward amount as with old stakings, diluting rewards for old stakers
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
Medium
A Medium severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#74
opened Jul 15, 2024 by
sherlock-admin4
jsmi - A voter lose bribe rewards if another voter voted before claim.
Escalation Resolved
This issue's escalations have been approved/rejected
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#52
opened Jul 15, 2024 by
sherlock-admin3
jennifer37 - Non-functional vote() if there is one bribe rewarder for this pool
Has Duplicates
A valid issue with 1+ other issues describing the same vulnerability
High
A High severity issue.
Reward
A payout will be made for this issue
Sponsor Confirmed
The sponsor acknowledged this issue is valid
Will Fix
The sponsor confirmed this issue will be fixed
#39
opened Jul 15, 2024 by
sherlock-admin2
ProTip!
What’s not been updated in a month: updated:<2024-12-15.