fyamf
Rankings
#66 2024
#238 All-time
#359 90-day
High-risk
16 Total
Medium-risk
13 Total
3 Solo
Activity
7 Audits
December 2024
19 December 2024
SecondSwap
Medium-risk
Selected for report
Medium-risk
Identified a finding grouped with:
Creator of one vesting plan can affect vesting plans created by other users.October 2024
25 October 2024
Kakarot
High-risk
Selected for report
September 2024
12 September 2024
Chakra
High-risk
Identified a finding grouped with:
Malicious actors can manipulate the `cross_chain_callback` callbackHigh-risk
Identified a finding grouped with:
SettlementSignatureVerifier is missing check for duplicate validator signaturesHigh-risk
Identified a finding grouped with:
There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` functionHigh-risk
Identified a finding grouped with:
Anyone can manipulate user nonce (nonce_manager) in settlement contractHigh-risk
Identified a finding grouped with:
SettlementSignatureVerifier is missing check for duplicate validator signaturesMedium-risk
Selected for report
High-risk
Identified a finding grouped with:
In Starknet already processed messages can be re-submitted and by anyoneMedium-risk
Selected for report
Medium-risk
Identified a finding grouped with:
Excessive Authority Granted to Managers in the `ckr_btc.cairo` Contract Presents Significant Management RisksHigh-risk
Identified a finding grouped with:
Anyone can manipulate user nonce (nonce_manager) in settlement contractHigh-risk
Identified a finding grouped with:
Invalid token address used in `ChakraSettlementHandler::cross_chain_erc20_settlement(...)` leading to invalid transaction creation and event emissionHigh-risk
Identified a finding grouped with:
In settlement.cairo::receive_cross_chain_msg - the payload_type can be passed by the user, confusing offchain systemsMedium-risk
Identified a finding grouped with:
Does not check if to_chain and to_handler is whitelisted in cross_chain_erc20_settlementMedium-risk
Identified a finding grouped with:
inconsistency in sender address when creating cross chain messages on Starknet can lead to loss of fundsJune 2024
18 June 2024
Olas
Medium-risk
Identified a finding grouped with:
checkpoint function is not called before staking which can cause loss of rewards for already staked services.Medium-risk
Selected for report
Medium-risk
Selected for report
May 2024
27 May 2024
Munchables
High-risk
Identified a finding grouped with:
Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens8 May 2024
Renzo
Medium-risk
Selected for report
High-risk
Identified a finding grouped with:
The amount of `xezETH` in circulation will not represent the amount of `ezETH` tokens 1:1Medium-risk
Identified a finding grouped with:
Deposits will always revert if the amount being deposited is less than the bufferToFill valueHigh-risk
Identified a finding grouped with:
Incorrect calculation of queued withdrawals can deflate TVL and increase ezETH mint rateMedium-risk
Selected for report