Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
Thunder Loan
Submissions
AI First Flight
Thunder Loan
AI First Flight #7
Beginner Friendly
Foundry
DeFi
Oracle
EXP
AI First Flight
EXP
Mar 12th, 2026 → Mar 12th, 2026
View repo
View results
10 / 10
Submissions
Severity
Validity
Tags
Author
#1
Flash loan repayment can be bypassed by calling deposit during the callback
High
Valid
[H-04] All the funds can be...
plarochkin
#2
Oracle relies on AMM spot price, making it vulnerable to flash loan manipulation
Medium
Valid
[M-02] Attacker can minimiz...
plarochkin
#3
Flash loan fee calculation has a severe unit mismatch (WETH vs underlying token)
High
Invalid
plarochkin
#4
Depositing tokens incorrectly inflates the exchange rate by a phantom fee
High
Valid
[H-02] Updating exchange ra...
plarochkin
#5
Incorrect exchange rate calculation formula in AssetToken
High
Valid
[H-02] Updating exchange ra...
plarochkin
#6
Removing an allowed token permanently locks user funds
Medium
Valid
[M-01] 'ThunderLoan::setAll...
plarochkin
#7
Upgraded contract uses initializer instead of reinitializer, breaking upgrades
High
Invalid
plarochkin
#8
Precision loss in fee calculation due to division before multiplication
Low
Valid
[L-01] getCalculatedFee can...
plarochkin
#9
AssetToken does not override the decimals() function
Low
Invalid
plarochkin
#10
Missing zero-address checks and uninitialized implementation contracts
Low
Invalid
plarochkin
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!