https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/b81f7108-d2eb-4e47-a11c-ff1193c62ba4.jpg

00xSEV

Security Researcher

Smart contract auditor https://t.co/k5qZvN8R8Y

Contact Me

High

10

Total

Medium

1

Solo

16

Total

$53.25K

Total Earnings

#172 All Time

11x

Payouts

gold

2x

1st Places

bronze

1x

3rd Places

regular

7x

Top 10

All

Sherlock

Code4rena

Cantina

CodeHawks

Hats Finance

Nov '24

collar-core

collar-core

1,197.53 USDC • 1 total finding • Cantina • 00xSEV

#9

medium

Finding not yet public.

sorella-angstrom

sorella-angstrom

3,513.28 USDC • 1 total finding • Cantina • 00xSEV

#5

medium

Finding not yet public.

May '24

Euler-v2

Euler-v2

28,026 USDC • Cantina • 00xSEV

gold

Apr '24

Exactly Protocol

Exactly Protocol

2,010.28 USDC • 1 total finding • Sherlock • 00xSEV

#6

high

`unassignedEarnings` in a fixed pool may become inaccessible

Mar '24

DittoETH

DittoETH

6,092.51 USDC • 1 total finding • Code4rena • 00xSEV

bronze

high

An attacker can cancel other people's short orders

Feb '24

Wise Lending

Wise Lending

7,312.25 USDC • 2 total findings • Code4rena • 00xSEV

#8

medium

`PendlePowerFarmToken:: totalLpAssetsToDistribute` may lead to temporary DOS due to price growth check being skipped during deposit

medium

Current Heartbeat Implementation May Lead to a Prolonged DoS for Chainlink Oracles

Wise Lending

Wise Lending

4,000 USDC • 1 total finding • Hats • 00xSEV

gold

medium

An attacker can DoS `enterFarm`

Jan '24

Salty.IO

Salty.IO

460.07 USDC • 6 total findings • Code4rena • 00xSEV

#27

high

When borrowers repay USDS, it is sent to the wrong address, allowing anyone to burn Protocol Owned Liquidity and build bad debt for USDS

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

high

The use of spot price by CoreSaltyFeed can lead to price manipulation and undesired liquidations

medium

formPOL lacks slippage and deadline protection

medium

Chainlink price feed uses BTC, not WBTC. In case of depegging, oracles will become easier to manipulate.

medium

Remove Liquidity has missing reserve1 DUST check, which can make reserve1 to be less than DUST

Dec '23

The Standard

The Standard

32.18 USDC • 3 total findings • CodeHawks • 00xSEV

#45

high

Rewards can be drained because of lack of access control

high

Looping over unbounded `pendingStakes` array can lead to permanent DoS and frozen funds

medium

Users can not remove some amount of collateral from contract because of wrong implementation of "canRemoveCollateral()"

Revolution Protocol

Revolution Protocol

205.52 USDC • 3 total findings • Code4rena • 00xSEV

#32

medium

Anyone can pause AuctionHouse in _createAuction

medium

CultureIndex.sol#dropTopVotedPiece() - Malicious user can manipulate topVotedPiece to DoS the whole CultureIndex and AuctionHouse

medium

It may be possible to DoS AuctionHouse by specifying malicious creators

Oct '23

NextGen

NextGen

398.86 USDC • 7 total findings • Code4rena • 00xSEV

#32

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

high

Attacker can reenter to mint all the collection supply

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders

medium

On a Linear or Exponential Descending Sale Model, a user that mint on the last `block.timestamp` mint at an unexpected price.

medium

Vulnerability in burnToMint function allowing double use of NFT

medium

The RandomizerVRF and RandomizerRNG not produce hash value.

medium

Auction winner can prevent payments via `safeTransferFrom` callback