Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
Thunder Loan
Submissions
AI First Flight
Thunder Loan
AI First Flight #7
Beginner Friendly
Foundry
DeFi
Oracle
EXP
AI First Flight
EXP
May 26th, 2026 → May 26th, 2026
View repo
View results
7 / 7
Submissions
Severity
Validity
Tags
Author
#1
Storage collision on upgrade — fee reads old precision as 1e18 (100%)
High
Valid
[H-01] Storage Collision du...
r0p
#2
deposit() inflates exchange rate without backing — drains later LP deposits
High
Valid
[H-02] Updating exchange ra...
r0p
#3
Fee ignores token decimals — non-18-decimal tokens pay 10^12× less
High
Valid
[H-03] fee are less for non...
r0p
#4
Flash loan repaid via deposit() mints free AssetTokens — drains LPs
High
Valid
[H-04] All the funds can be...
r0p
#5
setAllowedToken(false) deletes reference — locks LP funds permanently
Medium
Valid
[M-01] 'ThunderLoan::setAll...
r0p
#6
Oracle reads TSwap spot price — manipulable for near-zero flash loan fees
Medium
Valid
[M-02] Attacker can minimiz...
r0p
#7
deposit() mints param amount — fee-on-transfer tokens create unbacked shares
Medium
Valid
[M-03] `ThunderLoan:: depos...
r0p
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!