Skip to content
This repository has been archived by the owner on Dec 22, 2024. It is now read-only.

Issues: sherlock-audit/2024-05-elfi-protocol-judging

Author
Filter by author
Loading
Label
Filter by label
Loading
Use alt + click/return to exclude labels
or + click/return for logical OR
Projects
Filter by project
Loading
Milestones
Filter by milestone
Loading
Assignee
Filter by who’s assigned
Sort

Issues list

mstpr-brainbot - The redeem process updates the rewards in the wrong order Has Duplicates A valid issue with 1+ other issues describing the same vulnerability High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#274 opened Jun 20, 2024 by sherlock-admin2
ZeroTrust - In Cross Margin mode, the user’s profit calculation is incorrect. Escalation Resolved This issue's escalations have been approved/rejected High A valid High severity issue Reward A payout will be made for this issue Sponsor Disputed The sponsor disputed this issue's validity Won't Fix The sponsor confirmed this issue will not be fixed
#273 opened Jun 20, 2024 by sherlock-admin4
Salem - User Collateral Cap Check Issue Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#262 opened Jun 20, 2024 by sherlock-admin2
mstpr-brainbot - Users profit in short cross will leave the fees in UsdPool instead of LpPool High A valid High severity issue Reward A payout will be made for this issue Sponsor Disputed The sponsor disputed this issue's validity Won't Fix The sponsor confirmed this issue will not be fixed
#261 opened Jun 20, 2024 by sherlock-admin4
mstpr-brainbot - Mismatching funding fees can result in the protocol incurring a deficit or insolvency risk High A valid High severity issue Reward A payout will be made for this issue Sponsor Disputed The sponsor disputed this issue's validity Won't Fix The sponsor confirmed this issue will not be fixed
#258 opened Jun 20, 2024 by sherlock-admin4
aman - isHoldAmountAllowed and isSubAmountAllowed wrong subtraction will result in DoS Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#255 opened Jun 20, 2024 by sherlock-admin4
aman - The USer will receive less amount than user expected Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A valid Medium severity issue Reward A payout will be made for this issue Won't Fix The sponsor confirmed this issue will not be fixed
#251 opened Jun 20, 2024 by sherlock-admin3
mstpr-brainbot - Users can have positions with a margin lower than the allowed minimum margin Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Disputed The sponsor disputed this issue's validity Won't Fix The sponsor confirmed this issue will not be fixed
#249 opened Jun 20, 2024 by sherlock-admin4
ZeroTrust - The balance.unsettledAmount is missing in the calculations for getMaxWithdraw and isSubAmountAllowed in UsdPool.sol Escalation Resolved This issue's escalations have been approved/rejected Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#236 opened Jun 20, 2024 by sherlock-admin3
KrisRenZo - Use of outdated liability value in decreasePosition leads to account error Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#198 opened Jun 20, 2024 by sherlock-admin4
PNS - Future upgrades may be difficult or impossible Escalation Resolved This issue's escalations have been approved/rejected Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Won't Fix The sponsor confirmed this issue will not be fixed
#194 opened Jun 20, 2024 by sherlock-admin3
whitehair0330 - Incorrect implementation of the PositionMarginProcess.updatePositionFromBalanceMargin() function. Has Duplicates A valid issue with 1+ other issues describing the same vulnerability High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#163 opened Jun 20, 2024 by sherlock-admin2
0x486776 - Improper implementation of the PositionMarginProcess.updatePositionFromBalanceMargin() function. High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#159 opened Jun 20, 2024 by sherlock-admin4
KingNFT - A significant 105,983 gas cost of processExecutionFee() execution is not accounted in the keeper's compensation Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#147 opened Jun 20, 2024 by sherlock-admin4
dany.armstrong90 - Attacker can inflate stake rewards as he wants. Has Duplicates A valid issue with 1+ other issues describing the same vulnerability High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#146 opened Jun 20, 2024 by sherlock-admin3
KingNFT - Missing compensation for the 21,000 intrinsic gas cost Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#142 opened Jun 20, 2024 by sherlock-admin2
KingNFT - The keeper will suffer continuing losses due to miss compensation for L1 rollup fees Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#141 opened Jun 20, 2024 by sherlock-admin4
mstpr-brainbot - Minting stake tokens is not updating the pool's borrowing fee rate Has Duplicates A valid issue with 1+ other issues describing the same vulnerability High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#136 opened Jun 20, 2024 by sherlock-admin2
mstpr-brainbot - Updating leverage changes the cross net and cross available value High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#118 opened Jun 20, 2024 by sherlock-admin2
mstpr-brainbot - Excess fromBalance removal not added to other positions fromBalance's when leveraging up High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#117 opened Jun 20, 2024 by sherlock-admin4
mstpr-brainbot - Deleveraging can result in a zero borrowed amount while maintaining the leveraged position High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#114 opened Jun 20, 2024 by sherlock-admin4
tedox - Contract will reach a point where users will not be able to call deposit Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#113 opened Jun 20, 2024 by sherlock-admin3
mstpr-brainbot - Keepers loss gas is never accounted Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#108 opened Jun 20, 2024 by sherlock-admin4
mstpr-brainbot - Users can gas grief or completely block keepers from executing orders Has Duplicates A valid issue with 1+ other issues describing the same vulnerability Medium A valid Medium severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#107 opened Jun 20, 2024 by sherlock-admin3
mstpr-brainbot - If the stake token is minted from portfolio vault, positions from balances are not decreased High A valid High severity issue Reward A payout will be made for this issue Sponsor Confirmed The sponsor acknowledged this issue is valid Will Fix The sponsor confirmed this issue will be fixed
#106 opened Jun 20, 2024 by sherlock-admin2
ProTip! Adding no:label will show everything without a label.