| Finding | Target | Severity | Est. Payout | Status |
|---|---|---|---|---|
| dYdX V4 GetMegavaultEquity asymmetric mutation #261 | dYdX V4 (Cantina BB) | CRITICAL (Likelihood High, Impact High) | HIGH band 0K-150K modal (45%); CRITICAL 50K-500K possible (35%); confidence-weighted ~140K | SUBMITTED Cantina Finding #261 - 2026-05-12 05:02 UTC, Status New (awaiting triage). 5 evidence pillars + REDTEAMER POV + Why-not-informational pre-emption. Severity rationale maps to dYdX-published Critical-tier (unauthorized minting/printing of value). |
| Luno test_bridge.html bridge-enumeration / P3 info-disclosure floor | Luno (Bugcrowd) | P3 (P2 ceiling pending Cycle 21 runtime retry) | P3 floor ~$250-$1,500 (Bugcrowd Luno range); P2 ceiling ~$1-5K if Cycle 21 confirms LimitlessAuthoriseBid silent execution | BANKED 2026-05-12 via Cycle 20 static-deep-trace. P1 fund-withdrawal ceiling COLLAPSED (dispatcher allowlist rejects InitiateInstantBuy + InitiateWithdrawal). P3 floor CONFIRMED (test_bridge.html shipped to prod + dispatcher enumeration discloses production endpoint paths + gRPC service paths + payload structures). Kingsley deciding: ship-P3-now OR Cycle 21 runtime retry on BlueStacks/rooted Android for P2 upgrade. |
| Date | Target | Reason | Saved |
|---|---|---|---|
| 2026-05-12 | Day 27 actuator corpus (Allstate qa-roadside + IDnow video.test pair) | Cycle 18: 3 Tier-1 candidates only serve banner-grabbing endpoints (health/info/prometheus/metrics). High-value endpoints (env/heapdump/loggers/shutdown) all return 404. Rule 33 = unsubmittable. Day 27 249-host corpus retrospectively pre-classified. | ~30 min Buddy time + decisive Rule 33 calibration; don't re-audit Day 27 corpus |
| 2026-05-12 | Polymarket multi-audit Sub-rule 38.4 sweep (Cantina BB $5M pool) | Cycle 19: 1 DRIFT found = M-01 DELAY_PERIOD=0 (audit recommended INCREASING, team removed via PR #33), but that's the closed-Duplicate #570 finding per brief constraint. ALL other audit-asserted invariants HOLD in current HEAD across ChainSecurity Exchange + UMA + Multi-Outcome. | ~50 min Buddy time + Polymarket Sub-rule 38.4 surface confirmed saturated |
| 2026-05-12 | Luno test_bridge.html runtime PoC (Bugcrowd) | Cycle 20: P1 fund-withdrawal ceiling COLLAPSED via static-deep-trace. Dispatcher allowlist rejects InitiateInstantBuy + InitiateWithdrawal. Day 25 P1 hypothesis bust. P3 floor confirmed instead. | ~30 min + saved from false-P1-submission deposit burn |
| 2026-05-11 | Veda + Lombard + Aera + Renzo NatSpec Sub-rule 38.5 (Cycle 17) | 4/4 walk-clean on 38.5 retroactive sweep. ~697 NatSpec entries examined. Yield zone refined to un-audited-rich-NatSpec only. | ~60 min Buddy time + Sub-rule 38.5 yield zone decisively calibrated |
| 2026-05-11 | Hyperlane CCTP downstream deployers (Cycle 16, Sub-rule 38.3) | Hyperlane registry only contains Hyperlane-owned routes. 3rd-party CCTP warp-routes require chain-explorer bytecode-signature scanning (ARGUS-class multi-cycle). Banked for ARGUS EYE 13. | ~30 min + EYE 13 spec confirmed needed |
| 2026-05-11 | Hyperlane core Sub-rule 38.4 (Cycle 15-B) | Audit-asserted invariants HOLD on Hyperlane canonical deployments. Bug visible in source-only deployments (PR #8519 TokenBridgeCctp) walks Hyperlane's own scope. | ~45 min + Hyperlane 38.4 surface clean |
| 2026-05-11 | Aera v3 Sub-rule 38.4 (Cycle 14) | All audit-asserted invariants HOLD on current HEAD. Multi-firm audit discipline confirmed. | ~50 min |
| 2026-05-11 | Lombard Finance Sub-rule 38.4 (Cycle 13) | All audit-asserted invariants HOLD on current HEAD. | ~45 min |
| # | Rule | Date | Summary |
|---|---|---|---|
| RULE 43 | Rule 38 yield-targeting filter | 2026-05-11 | Pre-cycle audit-discipline scoring filters target list. Veda-class (multi-firm + recent cadence + clean prior outcomes) = HIGH-discipline LOW-yield = skip Rule 38 cycle entirely. Calibrated against 9 walks across Tier-1 Solidity perimeter. |
| RULE 42 | Walk-clean is a VALID verdict | 2026-05-11 | Walks compound methodology + indirect revenue (Securva positioning, Cantina rep, banked rules) even at $0 direct payout. Dual-revenue compound model. |
| RULE 41 | BB-velocity-favorable for Rule 38 | 2026-05-11 | Continuous BB programs (Immunefi/H1/BC/Cantina BB) > private contests (Cantina/C4/Sherlock) for Rule 38. Per-tier fixed rewards vs pool-split contest economics. dYdX (continuous BB, $1M Critical) > Polymarket (contest, $5M pool but cluster-split). |
| RULE 40 | Private-contest dup-blindness structural Gate 4 cap | 2026-05-11 | Cantina/C4/Sherlock SEAL submissions during contest window. Gate 4 cannot fire reliably. Polymarket #570 founder case (8-finder cluster). Dup-economics flatten upside even for 1st-finder. |
| RULE 38.5 | NatSpec / inline-doc implementation drift (Sub-rule) | 2026-05-12 (yield-zone-calibrated) | Code-only sister of 38.4. NatSpec/godoc/JSDoc/docstring claims vs implementation. Yield zone = un-audited-rich-NatSpec ONLY (skip already-audited per Cycle 17 4/4 walk). Skill v0.2 shipped. |
| RULE 38.4 | Audit-documented safety-net break (Sub-rule) | 2026-05-11 | Audit prose asserts invariant as established fact -> post-audit PR silently breaks it. HIGH-Critical regression class. dYdX V4 founder case (PR #2099 inverted DecommissionNonPositiveEquityVaults, broke line-980 invariant). Skill v0.1 shipped. |
| Tier | EYE | Type | Target | Detected |
|---|---|---|---|---|
| Tier-2 | EYE 12 | cantina-contest-state-change | Royco Dawn | 1h ago |
| Tier-2 | EYE 4 | github-commit-new | https://github.com/anza-xyz/agave | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.microsoft.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | itunes.apple.com | 1h ago |
| Tier-2 | EYE 10 | cname-migration-detected | api.pinterest.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | api.pinterest.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | chrome.google.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.shffls.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | hub.immutable.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | docs.immutable.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | api.us1.fga.dev | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | wiki.atom-lens.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.sophos.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | docs.sophos.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | www.assurancewireless.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | docsite.vistarmedia.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | transcodes-cdn.vistarmedia.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | digits.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | api.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | tfb.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | devedge.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | account.t-mobile.com | 1h ago |
| Tier-2 | EYE 10 | all-a-records-migrated | sprint.com | 1h ago |
| Tier-2 | EYE 3 | sourcemap-first-recovery | wallet.opensea.io | 3h ago |
| Tier-2 | EYE 4 | github-commit-new | https://github.com/anza-xyz/agave | 4h ago |
| Host | Path | Size | Files | Recovered |
|---|---|---|---|---|
| wallet.opensea.io | /assets/index-unKym5lB.js.map | 9197.9 KB | 1237 | 3h ago |
| wallet.opensea.io | /assets/index-C_N1jGkP.js.map | 9197.9 KB | 1237 | 2d ago |
| marketplace.auth0.com | /_next/static/chunks/pages/_app-5472c689... | 5696.1 KB | 1213 | 3d ago |
| marketplace.auth0.com | /_next/static/chunks/pages/index-f374b1d... | 0.5 KB | 1 | 4d ago |
| marketplace.auth0.com | /_next/static/chunks/framework-67c9938e3... | 183.8 KB | 9 | 4d ago |
| wallet.opensea.io | /assets/index-DGk1JYWX.js.map | 9197.9 KB | 1237 | 4d ago |
| marketplace.auth0.com | /_next/static/chunks/webpack-5aadf7b0e00... | 13.4 KB | 21 | 4d ago |
| marketplace.auth0.com | /_next/static/chunks/main-7e69766e8eff35... | 656.8 KB | 134 | 4d ago |
| clients.adstruc.com | /static/js/main.45ab4b31.js.map | 15953.6 KB | 2141 | 4d ago |
| wallet.opensea.io | /assets/index-BWT8Nbv7.js.map | 9197.9 KB | 1237 | 4d ago |
| Repo | Label | SHA | Message | Committed |
|---|---|---|---|---|
| coinbase/smart-wallet | security | e7fde11a50fa | Add SECURITY.md (#167) | 13d ago |
| Uniswap/v4-periphery | generic_bypass | 9dafaaecc1e2 | fix: pin npm to specific version in deploy workflow (#520) | 39d ago |
| babylonlabs-io/babylon | security | d00e68415909 | chore(deps): bump google.golang.org/grpc from 1.77.0 to 1.79.3 in the go_modules group acr | 48d ago |
| babylonlabs-io/babylon | security | 65d793a0a8b8 | ci: enhance backport workflow security (#1977) | 56d ago |
| Uniswap/UniswapX | security | 9c8f9017a694 | fix: resolve zizmor GitHub Actions security findings (#362) | 62d ago |
| Uniswap/v4-periphery | security | cfa74b47304d | fix: resolve zizmor GitHub Actions security findings (#515) | 62d ago |
| babylonlabs-io/babylon | security | 0a2d17d8df02 | chore(deps): bump the go_modules group across 1 directory with 4 updates (#1974) | 70d ago |
| dydxprotocol/v4-chain | security | 07b2c964e689 | upgrade cometbft and cosmos-sdk for tachyon security fix (#3320) | 105d ago |
| Uniswap/UniswapX | security | 687d9e122082 | fix(DCA): dca allocation bug (#360) | 108d ago |
| Uniswap/UniswapX | security | 898d71736220 | ci: integrate Nethermind Audit Agent for automated security scanning (#357) | 110d ago |
| Truelayer/truelayer-signing | security | 868e7e7c04ba | Bump Python library from 0.3.7 to 0.3.8 (#343) | 297d ago |
| Uniswap/v4-core | security | 5f00c8416c19 | Safer readme example (#961) | 404d ago |
| Title | Pool | Status | Ends |
|---|---|---|---|
| No active Sherlock contests right now. | |||
| Title | Transition | Pool | Detected |
|---|---|---|---|
| No Sherlock transitions yet. | |||
| Title | Pool | Status | Ends |
|---|---|---|---|
| No active Cantina contests right now. | |||
| Title | Transition | Pool | Detected |
|---|---|---|---|
| Royco Dawn | judging -> complete | $50,000 | 1h ago |
| Cluster | Members |
|---|---|
| FDJ-Kindred | 16 |
| ByteDance-TLB | 8 |
| Atlassian-Edge | 7 |
| Salesforce-Experience-Cloud | 6 |
| Apple-Geneva-Staging | 5 |
| Intergamma | 4 |
| IDnow | 2 |
| Mozilla-allizom-Staging | 2 |
| AutoDiscovered-GitRepo-intergamma/shopfront | 2 |
| Host | Note | Detected |
|---|---|---|
| - | state changed active->suspended (feed-membership) | 12h ago |
| - | state changed active->suspended (feed-membership) | 12h ago |
| - | state changed active->suspended (feed-membership) | 12h ago |
| - | state changed active->suspended (feed-membership) | 12h ago |
| - | state changed active->suspended | 12h ago |
| - | state changed active->suspended | 12h ago |
| - | state changed active->suspended | 12h ago |
| - | state changed active->suspended | 12h ago |