https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/2079ae77-6834-4cd9-a9f8-0bf34bbcf4d3.jpg

0xblackskull

Security Researcher

Web3 Security Researcher | Arch Linux Fanatic | Ex-Web2 Dev

Contact Me

High

5

Total

Medium

7

Total

$694.00

Total Earnings

#1430 All Time

12x

Payouts

regular

2x

Top 25

regular

6x

Top 50

All

Sherlock

Code4rena

Cantina

Sep '24

Royco Protocol

Royco Protocol

12.14 USDC • 1 total finding • Cantina • 0xblackskull

#61

high

Finding not yet public.

Apr '24

NOYA

NOYA

23.68 USDC + NOYA stars • 1 total finding • Code4rena • 0xblackskull

#76

medium

AccountingManager has no correct implementations of the core ERC-4626 functions `deposit`, `mint`, `withdraw` and `redeem`

Mar '24

Smart-contracts

Smart-contracts

131.77 USDC • 1 total finding • Cantina • 0xblackskull

#32

high

Finding not yet public.

Revert Lend

Revert Lend

6.61 USDC • 1 total finding • Code4rena • 0xblackskull

#70

medium

V3Oracle susceptible to price manipulation

Feb '24

AI Arena

AI Arena

246.18 USDC • 2 total findings • Code4rena • 0xblackskull

#22

medium

Minter / Staker / Spender roles can never be revoked`..,

medium

Burner role can not be revoked

Jan '24

Curves

Curves

0 USDC • 2 total findings • Code4rena • 0xblackskull

#137

high

Unauthorized Access to setCurves Function

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

2.76 USDC • Code4rena • 0xblackskull

#54

Oct '23

NextGen

NextGen

137.89 USDC • 1 total finding • Code4rena • 0xblackskull

#50

medium

Artist signatures can be forged to impersonate the artist behind a collection

Real Wagmi #2

Real Wagmi #2

88.51 USDC • 1 total finding • Sherlock • 0xblackskull

#17

high

Use of `slot0` to get `sqrtPriceLimitX96` can lead to price manipulation.

Sep '23

Venus Prime

Venus Prime

32.27 USDC • 1 total finding • Code4rena • 0xblackskull

#34

medium

DoS and gas griefing of calls to Prime.updateScores()

Maia DAO - Ulysses

Maia DAO - Ulysses

0.11 USDC • 1 total finding • Code4rena • 0xblackskull

#62

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

Centrifuge

Centrifuge

12.79 USDC • Code4rena • 0xblackskull

#34