https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

0x29A

Security Researcher

Contact Me

High

11

Total

Medium

10

Total

$10.92K

Total Earnings

#626 All Time

16x

Payouts

silver

1x

2nd Places

regular

3x

Top 10

regular

11x

Top 25

All

Code4rena

Jul '22

ENS contest

ENS contest

526.34 USDC • 2 total findings • Code4rena • 0x29A

#19

medium

transfer() depends on gas consts

medium

The `unwrapETH2LD` use `transferFrom` instead of `safeTransferFrom` to transfer ERC721 token

Fractional v2 contest

Fractional v2 contest

5,286.12 USDC • 7 total findings • Code4rena • 0x29A

silver

high

Users can lose fractions to precision loss during migraction if _newFractionSupply is set very low

high

Steal NFTs from a Vault, and ETH + Fractional tokens from users.

high

Malicious Users Can Exploit Residual Allowance To Steal Assets

high

Migration Module: Re-enter `commit` using custom token

medium

Migration fails when all tokens are joined

medium

Use of `payable.transfer()` may lock user funds

medium

The `FERC1155.sol` don't respect the EIP2981

Juicebox V2 contest

Juicebox V2 contest

1,303.56 USDC • 3 total findings • Code4rena • 0x29A

#10

high

ORACLE DATA FEED CAN BE OUTDATED YET USED ANYWAYS WHICH WILL IMPACT ON PAYMENT LOGIC

medium

Use a safe transfer helper library for ERC20 transfers

medium

Reentrancy issues on function `distributePayoutsOf`

Jun '22

Putty contest

Putty contest

52.65 USDC • 1 total finding • Code4rena • 0x29A

#73

medium

`fillOrder()` and `exercise()` may lock Ether sent to the contract, forever

Yieldy contest

Yieldy contest

657.92 USDC • 1 total finding • Code4rena • 0x29A

#18

medium

Possible DOS (out-of-gas) on loops.

Illuminate contest

Illuminate contest

602.51 USDC • 3 total findings • Code4rena • 0x29A

#22

high

Allowance check always true in ERC5095 redeem

high

ERC5095 redeem/withdraw does not update allowances

high

Illuminate PT redeeming allows for burning from other accounts

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

637.55 USDC • 4 total findings • Code4rena • 0x29A

#18

high

Overpayment of native ETH is not refunded to buyer

high

Accumulated ETH fees of InfinityExchange cannot be retrieved

high

`_transferNFTs()` succeeds even if no transfer is performed

medium

Malicious governance can use `updateWethTranferGas` to steal WETH from buyers