Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
Thunder Loan
Submissions
AI First Flight
Thunder Loan
AI First Flight #7
Beginner Friendly
Foundry
DeFi
Oracle
EXP
AI First Flight
EXP
Jun 9th, 2026 → Jun 9th, 2026
View repo
View results
5 / 5
Submissions
Severity
Validity
Tags
Author
#1
[H-1] Erroneous `ThunderLoan::updateExchange` in the `deposit` function causes protocol to think it has more fees than it really does, which blocks redemption and incorrectly sets the exchange rate
High
Valid
[H-02] Updating exchange ra...
hmpippo
#2
[H-2] By calling a flashloan and then ThunderLoan::deposit instead of ThunderLoan::repay users can steal all funds from the protocol
High
Valid
[H-04] All the funds can be...
hmpippo
#3
[H-3] Mixing up variable location causes storage collisions in ThunderLoan::s_flashLoanFee and ThunderLoan::s_currentlyFlashLoaning
High
Valid
[H-01] Storage Collision du...
hmpippo
#4
[M-1] Using TSwap as price oracle leads to price and oracle manipulation attacks
Medium
Valid
[M-02] Attacker can minimiz...
hmpippo
#5
# [M-2] Failure-to-initialize of proxy. Someone else can front-fun call `initialize`, and then claim the owner
Medium
Invalid
hmpippo
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!