https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/3bc61597-78c9-47d0-a1cf-9d4dc929bbf3.jpg

0xComfyCat

Security Researcher

smart contract stupid people

Contact Me

High

7

Total

Medium

3

Total

$9.16K

Total Earnings

#611 All Time

6x

Payouts

bronze

1x

3rd Places

regular

3x

Top 10

regular

4x

Top 25

All

Sherlock

Code4rena

Oct '23

The Wildcat Protocol

The Wildcat Protocol

16.79 USDC • 2 total findings • Code4rena • 0xComfyCat

#60

high

Lenders can escape the blacklisting of their accounts because they can move their MarketTokens to different accounts and gain the WithdrawOnly Role on any account they want

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

Aug '23

veRWA

veRWA

391.89 USDC • 3 total findings • Code4rena • 0xComfyCat

#8

high

When adding a gauge, its initial value has to be set by an admin or all voting power towards it will be lost

high

Voters from VotingEscrow can vote infinite times in vote_for_gauge_weights() of GaugeController

high

User don't have to deposit for a week into the market to get his weekly reward from the `LendingLedger`

Tangible Caviar

Tangible Caviar

2,520.87 USDC • Code4rena • 0xComfyCat

#6

Jul '23

Moonwell

Moonwell

434.74 USDC • 2 total findings • Code4rena • 0xComfyCat

#23

medium

Proposals which intend to send native tokens to target addresses can't be executed

medium

`fastTrackProposalExecution` doesn't check `intendedRecipient`

Amphora Protocol

Amphora Protocol

5,793.59 USDC • 2 total findings • Code4rena • 0xComfyCat

bronze

high

Rounding error in `WUSDA` can result in loss of user funds, especially when manipulated by an attacker

medium

When Convex pool is shut down while collateral type is `CurveLPStakedOnConvex`, users unable to deposit that asset and protocol lose the ability to accept the asset as collateral further

Tokemak

Tokemak

7.81 USDC • 1 total finding • Sherlock • 0xComfyCat

#52

high

LMPVaultRouterBase incorrectly handle WETH transfer