How it worksCompetitionsReviewsGuildsBountiesPortfolioBlog
Sign in

Superform / core-and-erc1155a

superform-xyzsuperformxyz

Overview

Leaderboard

Superform Competition

The competition at a glance:

  • November 27th 20:00 UTC to December 18th 20:00 UTC
  • $140,000 total prize pool.

Prize distribution and scoring

The prize distribution works as follows:

  • Security reviewers will score points for each finding.
  • Prizes are distributed proportionally to the number of points scored.
  • A High Severity is worth 10 points, and a Medium Severity 3 points.
  • Duplicate findings will be resolved using the following scoring formula that incentivizes unique findings:
    • Each duplicate finding will be scaled down by 0.9n1/n0.9^{n - 1} / n0.9n1/n, where nnn is the number of duplicates.
  • 10K USDC of the prize pot is reserved for Low Severity or Informational findings. These reports are judged based on quality and researchers are ranked from 1st to 5th for the purpose of prize allocation:
    • 1st: $5,000
    • 2nd: $2,500
    • 3rd: $1,250
    • 4th: $625
    • 5th: $625

Scope

Check out the previously recorded read through of the repos for both competitions on cantina twitter and here.

ERC1155A

  • Repository: superform-xyz/ERC1155A
  • Commit: e7d53f306989ba205c779973d1b5e86755a1b9c0
  • Total LOC: 388
  • Files: all files in src
FileBlankCommentCode
src/ERC1155A.sol100132362
src/aERC20.sol10726
SUM:110139388

Superform Core

FileBlankCommentCode
src/BaseRouterImplementation.sol143136773
src/crosschain-data/extensions/CoreStateRegistry.sol140130740
src/payments/PaymentHelper.sol147134574
src/crosschain-data/utils/PayloadHelper.sol6028339
src/crosschain-liquidity/DstSwapper.sol7554324
src/forms/ERC4626FormImplementation.sol7765279
src/SuperPositions.sol8071249
src/crosschain-data/adapters/layerzero/LayerzeroImplementation.sol5960235
src/settings/SuperRegistry.sol5877215
src/BaseForm.sol5559204
src/crosschain-data/extensions/TimelockStateRegistry.sol4848195
src/SuperformFactory.sol5855191
src/crosschain-liquidity/lifi/LiFiValidator.sol2759171
src/SuperformRouter.sol3123155
src/forms/ERC4626TimelockForm.sol3347153
src/crosschain-data/adapters/wormhole/automatic-relayer/WormholeARImplementation.sol4450153
src/crosschain-data/adapters/wormhole/specialized-relayer/WormholeSRImplementation.sol4659151
src/types/DataTypes.sol2639149
src/crosschain-data/adapters/hyperlane/HyperlaneImplementation.sol4657145
src/settings/SuperRBAC.sol3570120
src/crosschain-data/BaseStateRegistry.sol4148115
src/crosschain-data/BroadcastRegistry.sol283297
src/payments/PayMaster.sol282982
src/forms/ERC4626KYCDaoForm.sol142376
src/EmergencyQueue.sol283174
src/libraries/DataLib.sol101773
src/crosschain-liquidity/socket/SocketValidator.sol173072
src/BaseRouter.sol212965
src/forms/ERC4626Form.sol121856
src/crosschain-liquidity/socket/SocketOneInchValidator.sol172654
src/libraries/PayloadUpdaterLib.sol10649
src/crosschain-liquidity/BridgeValidator.sol101846
src/libraries/ArrayCastLib.sol10337
src/crosschain-liquidity/LiquidityHandler.sol81930
src/libraries/ProofLib.sol5216
src/crosschain-data/utils/QuorumManager.sol71713
SUM:155416696470

Out of Scope issues

Any findings on the previous review will be out of scope.

On top of that, automated findings from 4nalyzer will also be considered out of scope.

Summary

Status

Completed

Total reward:

$140,000 USDC

Start date:

27 Nov 2023 8:00pm (local time)

End date:

18 Dec 2023 8:00pm (local time)

The first marketplace for web3 security. We've aggregated the security talent and solutions so you don't have to.

Services

CompetitionsReviewsBountiesGuilds

© 2024 Cantina. All rights reserved.