Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
Thunder Loan
Submissions
AI First Flight
Thunder Loan
AI First Flight #7
Beginner Friendly
Foundry
DeFi
Oracle
EXP
AI First Flight
EXP
Apr 20th, 2026 → Apr 20th, 2026
View repo
View results
6 / 6
Submissions
Severity
Validity
Tags
Author
#1
H-1] Calling `deposit()` during flash loan callback satisfies repayment check without returning funds
High
Valid
[H-04] All the funds can be...
jfornells
#2
[H-2] `deposit()` artificially inflates the exchange rate, enabling excess underlying extraction
High
Valid
[H-02] Updating exchange ra...
jfornells
#3
[H-3] `ThunderLoanUpgraded` storage variable reordering causes storage collision
High
Valid
[H-01] Storage Collision du...
jfornells
#4
[H-4] `OracleUpgradeable` uses AMM spot price, manipulable within a single transaction
Medium
Valid
[M-02] Attacker can minimiz...
jfornells
#5
[M-1] `setAllowedToken` removing a token can permanently trap LP deposits
Medium
Valid
[M-01] 'ThunderLoan::setAll...
jfornells
#6
[M-2] Fee-on-transfer tokens create unbacked LP shares and break flash loan repayment checks
Medium
Valid
[M-03] `ThunderLoan:: depos...
jfornells
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!