-
Notifications
You must be signed in to change notification settings - Fork 4
Issues: code-423n4/2024-04-panoptic-findings
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Author
Label
Projects
Milestones
Assignee
Sort
Issues list
Attacker can mint long position with dust amount to make a loss to protocol
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
duplicate-313
grade-b
Q-01
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
🤖_352_group
AI based duplicate group recommendation
#581
opened Apr 22, 2024 by
c4-bot-6
Nondeterministic clone can cause issues in case of reorg
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
grade-a
primary issue
Highest quality submission among a set of duplicates
Q-02
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
#573
opened Apr 22, 2024 by
c4-bot-1
QA Report
bug
Something isn't working
grade-a
Q-03
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
selected for report
This submission will be included/highlighted in the audit report
#568
opened Apr 22, 2024 by
c4-bot-8
Return values of Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
grade-a
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
approve()
not checked
bug
#565
opened Apr 22, 2024 by
c4-bot-4
maxMint()
violates EIP-4626
bug
#553
opened Apr 22, 2024 by
c4-bot-2
Lack of Arbitrum Sequencer Uptime Checks in CollateralTracker Contract
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
grade-a
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
#546
opened Apr 22, 2024 by
c4-bot-8
Median is not updated when burning a position, which can result in an inaccurate solvency check
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
grade-a
primary issue
Highest quality submission among a set of duplicates
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
sponsor disputed
Sponsor cannot duplicate the issue, or otherwise disagrees this is an issue
#540
opened Apr 22, 2024 by
c4-bot-9
PanopticFactory
uses spot price when deploying new pools, resulting in liquidity manipulation when minting
2 (Med Risk)
#537
opened Apr 22, 2024 by
c4-bot-7
haircutPremia
will not cover protocol losses using liquidatee long premiums
bug
#534
opened Apr 22, 2024 by
c4-bot-6
PanopticFactory
can be bricked and become unusable
bug
#523
opened Apr 22, 2024 by
c4-bot-8
MaxLimit is not implemented in minting
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
duplicate-501
grade-b
Q-10
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
🤖_61_group
AI based duplicate group recommendation
satisfactory
satisfies C4 submission criteria; eligible for awards
#513
opened Apr 22, 2024 by
c4-bot-9
_validatePositionList()
does not check for duplicate tokenIds, allowing attackers to bypass solvency checks
2 (Med Risk)
#498
opened Apr 22, 2024 by
c4-bot-3
SettleLongPremium
is incorrectly implemented: premium should be deducted instead of added
3 (High Risk)
#497
opened Apr 22, 2024 by
c4-bot-6
CREATE2
address collision during pool deployment allows for complete draining of the pool
2 (Med Risk)
#482
opened Apr 22, 2024 by
c4-bot-10
Incorrect validation during checking liquidity spread
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
M-04
🤖_479_group
AI based duplicate group recommendation
satisfactory
satisfies C4 submission criteria; eligible for awards
selected for report
This submission will be included/highlighted in the audit report
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
#479
opened Apr 22, 2024 by
c4-bot-10
Malicious users will purchase dust amount of options to prevent option sellers from burning their options
bug
Something isn't working
downgraded by judge
Judge downgraded the risk level of this issue
grade-b
primary issue
Highest quality submission among a set of duplicates
Q-12
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
🤖_312_group
AI based duplicate group recommendation
sponsor disputed
Sponsor cannot duplicate the issue, or otherwise disagrees this is an issue
#473
opened Apr 22, 2024 by
c4-bot-10
Panoptic pool can be non-profitable by specific Uniswap governance
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
M-05
primary issue
Highest quality submission among a set of duplicates
🤖_138_group
AI based duplicate group recommendation
satisfactory
satisfies C4 submission criteria; eligible for awards
selected for report
This submission will be included/highlighted in the audit report
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
#469
opened Apr 22, 2024 by
c4-bot-7
_updateSettlementPostBurn() may not correctly reduce s_grossPremiumLast[chunkKey]
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
M-06
satisfactory
satisfies C4 submission criteria; eligible for awards
selected for report
This submission will be included/highlighted in the audit report
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
#462
opened Apr 22, 2024 by
c4-bot-10
When Burning a Tokenized Position Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
M-07
🤖_97_group
AI based duplicate group recommendation
satisfactory
satisfies C4 submission criteria; eligible for awards
selected for report
This submission will be included/highlighted in the audit report
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
validate
should be done before flipping the isLong
bits in _validateAndForwardToAMM()
2 (Med Risk)
#459
opened Apr 22, 2024 by
c4-bot-4
Previous Next
ProTip!
Add no:assignee to see everything that’s not assigned.