https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/4a28d593-96bd-4437-9b6f-68b3e8bac9bd.jpg

0xJuda

Security Researcher

I am aspiring to become a web3 auditor and work in this great space of opportunities.

Contact Me

High

10

Total

Medium

7

Total

$2.64K

Total Earnings

#931 All Time

6x

Payouts

regular

2x

Top 10

regular

3x

Top 25

regular

4x

Top 50

All

Sherlock

Code4rena

CodeHawks

Oct '23

NextGen

NextGen

3.39 USDC • 4 total findings • Code4rena • 0xJuda

#100

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

high

Attacker can reenter to mint all the collection supply

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders

medium

Auction winner can prevent payments via `safeTransferFrom` callback

Real Wagmi #2

Real Wagmi #2

574.03 USDC • 2 total findings • Sherlock • 0xJuda

#8

high

Lender burning his position makes complete repayment of borrow position impossible

high

Absence of Slippage Protection in LiquidityBorrowingManager#repay

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

10.81 USDC • 4 total findings • CodeHawks • 0xJuda

#151

high

Sandwich attack to steal all ERC-20 tokens in the Fees contract

high

Forcing a borrower to pay a huge debt via the giveLoan()

medium

No expiration deadline leads to losing a lot of funds

medium

Fixed fee level is used when swap tokens on Uniswap

CodeHawks Escrow Contract - Competition Details

CodeHawks Escrow Contract - Competition Details

1,867.81 USDC • 4 total findings • CodeHawks • 0xJuda

#7

medium

[H-01] Lack of emergency withdraw function when no arbiter is set

medium

High - Funds can be lost if any participant is blacklisted

medium

Fixed `i_arbiterFee` can prevent payment

low

Constructor of `Escrow` should make sure that `buyer`, `seller`, `arbiter` are different from each other.

Tokemak

Tokemak

102.40 USDC • 3 total findings • Sherlock • 0xJuda

#43

high

User can transfer LMPVault shares to claim rewards multiple times

high

Router double accounting problem and exposed funds in smart contract

high

Liquidations miss delegate call to swapper

Jun '23

Unitas Protocol

Unitas Protocol

81.25 USDC • 1 total finding • Sherlock • 0xJuda

#18

medium

Stale price leads to user getting incorrect token amount