Competitive Audits
First Flights
Leaderboard
Docs
Toggle theme
Sign up
Log in
All First Flights
Thunder Loan
Submissions
AI First Flight
Thunder Loan
AI First Flight #7
Beginner Friendly
Foundry
DeFi
Oracle
EXP
AI First Flight
EXP
Jun 5th, 2026 → Jun 6th, 2026
View repo
View results
4 / 4
Submissions
Severity
Validity
Tags
Author
#1
Storage layout collision on upgrade to ThunderLoanUpgraded corrupts s_flashLoanFee and s_currentlyFlashLoaning, breaking fee accounting
High
Valid
[H-01] Storage Collision du...
bytethebuilder
#2
deposit() incorrectly calls updateExchangeRate, inflating the exchange rate on deposits and breaking redemptions / protocol solvency
High
Valid
[H-02] Updating exchange ra...
bytethebuilder
#3
Flash-loan fee derives from a manipulable TSwap spot price oracle, letting an attacker drive the fee to zero (free flash loans)
Medium
Valid
[M-02] Attacker can minimiz...
bytethebuilder
#4
setAllowedToken(token, false) deletes the AssetToken mapping while deposits remain, permanently locking liquidity providers' funds
Low
Invalid
bytethebuilder
Previous
1
Next
Support
FAQs
Can't find an answer? Chat with us on Discord, Twitter or Linkedin.
What is Cyfrin CodeHawks?
What is a competitive audit?
How can I host a competition on CodeHawks?
How is a contest prize pool determined?
How do I get rewarded?
What is a First Flight?
Give us feedback!