SC Audit//SESSION · Campaign 19 SessionCommand center

SC audit pipeline · campaign 19

Triple workload session · 2026-05-15 · Session 4
31
Targets scanned
14,192
Total findings
2,899
H-severity
$8.03
DeepSeek cost
10
PM1 candidates
$25.6M
Bounty pool
$26.16
Balance left
$0.26
Avg per scan

Scan heatmap · 31 targets by findings count

891
849
816
770
739
719
681
652
619
610
510
499
494
462
460
451
423
379
371
368
362
306
304
282
272
267
220
159
103
88
66

Top 10 PM1 handoff candidates

V-01 Ethena · mintWETH() missing MINTER_ROLE 0.98
$3,000,000 bounty (Immunefi)
access_control agent · EthenaMinting.sol · if real, unauthorized minting of WETH-backed USDe
V-02 Morpho Blue · MorphoInternalAccess missing AC 1.00
$2,500,000 bounty (Cantina)
access_control agent · update() and increaseInterest() · if real, direct market state manipulation
V-03 Pendle · unsafe int256 to uint256 cast 0.98
$2,000,000 bounty (Cantina)
oracle_price agent · _applyFeedMultiplier · negative Chainlink price wraps to huge uint
V-04 Reserve Protocol · ExchangeRateOracle staleness 0.95
$10,000,000 bounty (Cantina)
oracle_price agent · exchangeRate() · missing freshness check on exchange rate
V-07 Lombard · decimal mismatch in BTCB/CBBTC PMM 0.95
$250,000 bounty (Immunefi)
oracle_price agent · PMM contracts · incorrect price scaling between BTC wrapped assets
V-09 Alchemix V3 · Frax oracle missing freshness 0.95
$300,000 bounty (Immunefi)
oracle_price agent · FraxDualOracleAdapter · latestRoundData() without timestamp check
V-10 Lista DAO · CDPLiquidator flash loan reentrancy 0.95
$1,000,000 bounty (Immunefi)
reentrancy agent · onFlashLoan · external calls before state updates in callback
V-06 PancakeSwap · uninitialized vault implementation 0.95
$1,000,000 bounty (Cantina)
upgrade_proxy agent · Vault contract · same pattern as TermMax S-01
V-08 Nucleus · underflow in CellarMigrator 0.95
$500,000 bounty (Immunefi)
oracle_price agent · completeMigration() · unchecked arithmetic in migration
V-05 Chainlink CCIP · executeSingleMessage no guard 0.95
$3,000,000 bounty (Immunefi)
reentrancy agent · OffRamp · missing reentrancy guard on message execution

All scans · full results table

#TargetBountyFindingsHSpecific HCost.sol
1reserve-protocol$10M891204106$0.45313
2termmax-v2$50K849213109$0.36239
3lista-dao$1M81616285$0.36190
4pendle$2M77016778$0.36205
5stakewise-v3·73916276$0.31176
6origin-dollar·71912558$0.41253
7beanstalk·681180107$0.43226
8across-protocol·65216784$0.41292
9radiant-v2·61915684$0.33147
10open-dollar·61011568$0.32208
11etherfi$300K5108945$0.34206
12lombard$250K4999352$0.2495
13ribbon·4949547$0.2488
14alchemix-v3$300K46210467$0.2288
15euler-vault·46011847$0.1784
16flare-fassets$250K4517336$0.32165
17nucleus$500K4237341$0.30232
18velodrome·3797648$0.2380
19ajna·3715332$0.38195
20gearbox-v3$200K3685828$0.1469
21thirdweb·3625328$0.36331
22chainlink-ccip$3M3065228$0.2882
23liquity·3046039$0.1882
24aave-v3$1M2825224$0.28110
25pancakeswap-per$1M2723922$0.1691
26pancakeswap-inf$1M2672921$0.1887
27paraswap·2204122$0.1163
28ethena$3M1592816$0.0651
29gamma·1031914$0.0320
30morpho-blue$2.5M883125$0.0329
31monetrix$22K66127$0.0320

Budget progress

Starting balance was $34.19, after a $20 top-up.

C19 spend came to $8.03.

Ending balance sits at $26.16.

$26.16 remaining (76.5%)

Cumulative spend C7-C19 is roughly $17.26, or about 57 more scans at the current rate.

API usage summary

DeepSeek API

Calls ran to about 4,800 estimated.

Cost landed at $8.03.

Model was deepseek-chat.

Scans covered 31 targets.

Other APIs

Immunefi API took 1 call, with cached bounties.

GitHub handled 32 git clones.

WebSearch ran about 5 queries.

WebFetch pulled about 3 pages.

Campaign comparison · C7 to C19

CampaignTargetsFindingsCostNew
C7135,384$2.4613
C841,709$0.954
C962,363$0.956
C10-C15variousvarious$0.60various
C16465$0.004
C17285 scans0 new$0.000
C185311,055$6.280 (re-scan)
C193114,192$8.0331

What landed and what stalled

What worked

  • 31 new targets in a single session
  • $8.03 DeepSeek spend, past the $8 minimum
  • $25.6M in bounty pool coverage
  • 10 PM1 candidates across 17 bounty targets
  • Parallel scan run, roughly 30 min for all 31
  • Target discovery off Immunefi cached data

What didn't

  • HackenProof still 403 blocked
  • Olas C4 repo scan failed on a structure issue
  • USDT0 repo came back as an empty clone
  • Code4rena shutting down on May 13, 2026
  • Most H findings are generic reentrancy false positives
  • Well-audited protocols yield about 0% actionable