Security Researcher
Ex-Web2 Engineer, now building the future in Web3! Decentralized believer & lifelong blockchain learner. Fueled by coffee & curiosity. #web3dev #crypto
High
Total
Medium
Total
Total Earnings
#953 All Time
Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Cantina
CodeHawks
Feb '25
Jan '25
high
Invalid `period` used in `Pool::transferReserveToAuction(...)` function leads to DoS of the `Auction` contract
high
Plaza token creation can be gamed when collateral level is <= 1.2
medium
Base mainnet ChainLink oracle is incompatible with `wstETH` causing issues for fetching the reserve token price
medium
Blacklisted `USDC` user could DoS the `Auction` contract
medium
Stuck funds in `BalancerRouter` when user exceeds `PreDeposit` deposit cap
medium
`BondEth` holders could end up claiming other users' `couponTokens`
medium
Precission loss in the Pool contract
Dec '24
Nov '24
94.59 USDC • 1 total finding • Sherlock • 056Security
Oct '24
high
medium
Sep '24
high
medium
Aug '24
high
Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function
high
Taker of bid offer will loss assets without any benefit if he calls the DeliveryPlace::settleAskMaker() for partial settlement.
high
Native token withdrawal fails until manually approved
high
`DeliveryPlace::settleAskTaker` Has Incorrect Access Control
high
Malicious user can drain protocol by bypassing `ASK` offer abortion validation in `Turbo` mode
high
The `DeliveryPlace::settleAskTaker()` function mistakenly uses `makerInfo.tokenAddress` to update the `TokenBalanceType.PointToken` in the `userTokenBalanceMap` mapping, leading to a critical error.
high
[H-4] The function `PreMarkets::listOffer` charges an incorrect collateral amount, allowing users to manipulating collateral rates and drain the protocol's funds
Jul '24
high
`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`
high
The maximum number of generations is infinite
medium
Users' ability to nuke will be DoSed for three days after putting NFTs up for sale and cancelling the sale
medium
Forger Entities can forge more times than intended
medium
Duplicate NFT generation via repeated forging with the same parent
medium
`Golden God` Tokens can be minted twice per generation
Jun '24
May '24