SECURITY AUDIT REGISTRY

Competitive audit participation and vulnerability disclosure record

// AUDIT PLATFORM PROFILES
#001

RAAC

CodeHawksCodeHawks
RANK: 136thREPORT
FINDINGS:HIGH: 4MED: 5LOW: 3
// KEY FINDING

Identified critical reentrancy vulnerability in the tokenization flow allowing unauthorized asset minting. Exploitable via external contract callback during state transition.

#002

Symmio (Staking & Vesting)

SherlockSherlock
RANK: 11thREPORT
FINDINGS:HIGH: 1
// KEY FINDING

Identified precision loss bug in staking reward distribution where 18-decimal arithmetic causes USDC rewards to round down to zero, resulting in stakers receiving no USDC rewards despite funding being notified.

#003

Yieldoor

SherlockSherlock
RANK: 15thREPORT
FINDINGS:HIGH: 1MED: 1
// KEY FINDING

Found incorrect repayment calculation in the withdraw function where amountOut0 is used instead of amountOut1 when token1 is the borrowed asset, causing under-repayment of debt and leaving positions undercollateralized.

#004

Super DCA Liquidity Network

SherlockSherlock
RANK: 49thREPORT
FINDINGS:MED: 1
// KEY FINDING

Discovered missing reward index update in setMintRate, allowing mint rate changes to retroactively affect unaccrued rewards — stakers receive more or less than owed for past periods depending on the direction of the rate change.

#005

Concrete

Code4renaCode4rena
RANK: 101stREPORT
FINDINGS:MED: 1
// KEY FINDING

Finding details are under NDA — contest report is private.

#006

Liquid Ron

Code4renaCode4rena
RANK: 74thREPORT
FINDINGS:HIGH: 1MED: 1
// KEY FINDING

Uncovered reward compounding logic error causing permanent fund lock when claiming during validator slashing events on Ronin chain.

#007

Yeet

ImmunefiImmunefi
RANK: 40thREPORT
FINDINGS:INSIGHTS: 2
// KEY FINDING

Submitted architectural improvements for pool mechanics on Berachain, focusing on gas optimization patterns for high-frequency gamified interactions.

7
CONTESTS
7
HIGH SEVERITY
9
MEDIUM SEVERITY
3
LOW SEVERITY