Banner
https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/1de94d07-b961-4a8b-ab92-5f4aa7325f89.png

0xJoyBoy03

Security Researcher

That's weird. web3 gets safer when I rock in this industry 🤘 🎸 You can now take a relief breath cause I'm here https://github.com/moeid3/Audits

Contact Me

High

10

Total

Medium

5

Total

$1.60K

Total Earnings

#1128 All Time

7x

Payouts

bronze

2x

3rd Places

regular

3x

Top 10

regular

3x

Top 25

All

Sherlock

Code4rena

Apr '25

Aegis.im YUSD

Aegis.im YUSD

139.83 OP • 1 total finding • Sherlock • 0xJoyBoy03

bronze

medium

Attacker can prevent others from making a redeem request forever

Jul '24

TraitForge

TraitForge

72.9 USDC • 5 total findings • Code4rena • 0xJoyBoy03

#47

high

The maximum number of generations is infinite

high

Number of entities in generation can surpass the 10k number

high

Griefing attack on seller's airdrop benefits

high

Wrong minting logic based on total token count across generations

medium

Discrepancy between nfts minted, price of nft when a generation changes & position of `_incrementGeneration()` inside `_mintInternal()` & `_mintNewEntity()`

Jun '24

Size

Size

72.8 USDC • 3 total findings • Code4rena • 0xJoyBoy03

#45

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

high

When `sellCreditMarket()` is called to sell credit for a specific cash amount, the protocol might receive a lower swapping fee than expected.

medium

Users can not to buy/sell minimum credit allowed due to exactAmountIn condition

May '24

LoopFi

LoopFi

386.08 USDC • 1 total finding • Code4rena • 0xJoyBoy03

bronze

high

Availability of deposit invariant can be bypassed

Apr '24

NOYA

NOYA

62.86 USDC + NOYA stars • 2 total findings • Code4rena • 0xJoyBoy03

#54

high

In Dolomite, when opening a borrow position, the holding position in the Registry will never be updated due to the removePosition flag being set to true

medium

Missing calls to `_updateTokenInRegistry` leads to incorrect state of tokens in registry

Mar '24

PoolTogether

PoolTogether

1.47 USDC • 1 total finding • Code4rena • 0xJoyBoy03

#29

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

864.44 USDC • 2 total findings • Code4rena • 0xJoyBoy03

#4

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

medium

Malicious users can prevent holders from claiming their rewards during a reward cycle by skipping it.