Skip to content

code-423n4/redacted-bug-bounty

View on GitHub ↗Related repositories →

active 2023-12-202025-10-01 (UTC)

Complete coverage26,676 / 26,676 hourly files (100%) · 2 absent upstream2023-08-152026-08-30 (UTC)
Events
234
Pushes
10
Pull requests
2
Issues
187
Stars
18
Forks
12

Activity over time

Daily event counts in the loaded window

Line chart, 652 days from 2023-12-20 to 2025-10-01. Pushes: 10 total, peak 3 in a day. Pull requests: 2 total, peak 2 in a day. Issues: 187 total, peak 26 in a day. Comments: 0 total, peak 0 in a day. Stars: 18 total, peak 1 in a day.

  • Pushes
  • Pull requests
  • Issues
  • Comments
  • Stars

Stars, PRs, issues and forks are under-captured in the later part of this window. GH Archive progressively stopped capturing non-push events during 2026 — −95% or worse by the end of the window. Every series here except Pushes fades for that reason, so a decline above reflects the archive, not this repository. Pushes stay reliable throughout, so read them, and the contributor counts derived from them, as the real signal. Data health has the measurements.

Top contributors

Pushes, PRs, issues, reviews and comments — stars and forks excluded, so this is contribution rather than popularity

ContributorContributionsPushesPRsComments
c4-bot-834000
c4-bot-928000
c4-bot-1028000
c4-bot-324000
c4-bot-622000
c4-bot-417000
c4-bot-712000
c4-bot-28000
c4-bot-18000
c4-bot-56000
itsmetechjay5500
kartoonjoy5320
sentinelxyz1100
CloudEllie1100

Recent activity

Latest issues, pull requests and releases

  • Issue#237c4-bot-92025-09-23 15:02
    DoS or Message drop via pre-increment of processedNonce
  • Issue#238c4-bot-32025-09-23 15:02
    Reentrancy double-processing or DoS risk from external call performed before marking message processed
  • Issue#235c4-bot-42025-09-23 15:02
    DoS with (Unexpected) revert in multi-recipient payout (strict split leaves funds stuck)
  • Issue#233c4-bot-102025-07-25 13:52
    Unlimited Unbacked Token Minting via OFTLockbox
  • Issue#231c4-bot-102025-07-25 13:52
    Unbacked Token Minting via Malicious lzCompose Message in OFTLockbox
  • Issue#230c4-bot-102025-07-25 13:52
    Oracle Sync Lag Exploited for Under-Collateralized pxUSD Mint & PSM Reserve Drain
  • Issue#228c4-bot-82025-07-25 13:52
    Fast sync pxETH overmint leads to permanent undercollateralization
  • Issue#226c4-bot-82025-07-25 13:52
    BrandedLST totalSupply can exceed pxETH backing in Lockbox (invariant violation & systemic insolvency)
  • Issue#223c4-bot-42025-07-25 13:52
    RateLimiter can be bypassed via batch withdrawal fragmentation, allowing over-limit ETH drains
  • Issue#221c4-bot-42025-07-25 13:51
    LiquidStakingTokenLockbox accepts unauthenticated LayerZero fast sync messages — enables unbacked pxETH minting
  • Issue#218c4-bot-82025-07-07 08:37
    Race Condition via Forged Sync in LiquidStakingTokenLockbox Allows ETH Theft Without Bridging
  • Issue#217c4-bot-92025-07-07 08:37
    THE INVERTIBILITY FALLACY IN DINEROERC20REBASE
  • Issue#216c4-bot-82025-07-07 08:37
    Phantom Liquidity Extraction via Desynchronized Pending Deposits in LiquidStakingTokenLockbox
  • Issue#214c4-bot-92025-07-07 08:36
    CASE 001: Cross-chain message validation missing
  • Issue#213c4-bot-92025-07-07 08:36
    Cross chain reentrancy
  • Issue#209c4-bot-82025-07-07 08:36
    🔥 CRITICAL VULNERABILITY REPORT #03
  • Issue#208c4-bot-92025-07-07 08:36
    🔥 CRITICAL VULNERABILITY REPORT #02
  • Issue#207c4-bot-82025-07-07 08:36
    🔥 HIGH SEVERITY VULNERABILITY REPORT #04
  • Issue#205c4-bot-82025-07-07 08:36
    HIGH SEVERITY VULNERABILITY REPORT #06
  • Issue#202c4-bot-32025-07-07 08:35
    Oracle Manipulation Leading to Unbacked Token Minting
  • Issue#199c4-bot-42025-07-07 08:35
    Withdrawal Bypass Through Pending Deposit Manipulation
  • Issue#197c4-bot-82025-07-07 08:35
    Critical Vulnerability Report: LiquidStakingTokenLockbox.sol
  • Issue#195c4-bot-82025-07-07 08:35
    Incorrect Asset and Share Calculation in Withdrawal Flow
  • Issue#194c4-bot-92025-07-07 08:19
    Inconsistent Event Emission in _burnShares Function of DineroERC20RebaseUpgradeable Causes Misleading Token Value Reporting
  • Issue#193c4-bot-62025-07-07 08:19
    Unprotected distributeFees() Allows Unauthorized ERC20 Transfers in PirexFees.sol

Totals cover only the window loaded into ClickHouse and count events, not GitHub's lifetime totals — 18 stars here means stars gained during the window, not the repo's star count.