https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/2f24cb27-a67e-4667-aec2-39292d0cf032.jpg

0xepley

Security Researcher

4e5341198a

Contact Me

High

9

Total

Medium

7

Total

$3.29K

Total Earnings

#921 All Time

23x

Payouts

regular

3x

Top 10

regular

11x

Top 25

regular

20x

Top 50

All

Sherlock

Code4rena

CodeHawks

Mar '24

Acala

Acala

98.99 USDC • Code4rena • 0xepley

#15

Smart Wallet

Smart Wallet

264.73 USDC • Code4rena • 0xepley

#8

Taiko

Taiko

423.58 USDC • Code4rena • 0xepley

#23

PoolTogether

PoolTogether

440.81 USDC • Code4rena • 0xepley

#12

Phat Contract Runtime

Phat Contract Runtime

59.23 USDC • Code4rena • 0xepley

#11

Feb '24

UniStaker Infrastructure

UniStaker Infrastructure

22.02 USDC • Code4rena • 0xepley

#8

Wise Lending

Wise Lending

319.93 USDC • Code4rena • 0xepley

#23

AI Arena

AI Arena

166.17 USDC • Code4rena • 0xepley

#34

Jan '24

MorpheusAI

MorpheusAI

2.82 USDC • 1 total finding • CodeHawks • 0xepley

#27

low

Any User can mint any amount of WStETH in the WStETHMock.sol and StETHMock.sol

Decent

Decent

186.24 USDC • Code4rena • 0xepley

#28

Salty.IO

Salty.IO

39.34 USDC • Code4rena • 0xepley

#96

Opus

Opus

100.1 USDC • Code4rena • 0xepley

#17

Curves

Curves

120.1 USDC • Code4rena • 0xepley

#41

reNFT

reNFT

269.86 USDC • Code4rena • 0xepley

#31

Dec '23

The Standard

The Standard

0.16 USDC • 2 total findings • CodeHawks • 0xepley

#96

high

Looping over unbounded `pendingStakes` array can lead to permanent DoS and frozen funds

medium

Missing deadline check allow pending transactions to be maliciously executed

Nov '23

Shell Protocol

Shell Protocol

44.92 USDC • Code4rena • 0xepley

#10

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

19.04 USDC • Code4rena • 0xepley

#26

Kelp DAO | rsETH

Kelp DAO | rsETH

137.31 USDC • 1 total finding • Code4rena • 0xepley

#31

high

Protocol mints less rsETH on deposit than intended

Sep '23

DittoETH

DittoETH

62.95 USDC • 3 total findings • CodeHawks • 0xepley

#40

low

No check if bridge already exists

low

Loss of precision in `twapPriceInEther` due to division before multiplication

low

`onERC721Received()` callback is never called when new tokens are minted in Erc721Facet.sol

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

124.35 USDC • Code4rena • 0xepley

#50

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

287.16 USDC • 9 total findings • CodeHawks • 0xepley

#12

high

Sandwich attack to steal all ERC-20 tokens in the Fees contract

high

[H-04] Lender#buyLoan - Malicious user could take over a loan for free without having a pool because of wrong access control

high

Attacker can steal a loan's collateral and break the protocol

high

Fee on transfer tokens will cause users to lose funds

high

update() not getting called right after a WETH amount has been sent will cause users to lose staking rewards

medium

The `borrow` and `refinance` functions can be front-run by the pool lender to set high interest rates

medium

If a borrower or lender got blacklisted by asset contract, their collateral or loan funds can be permanently frozen with the pool

medium

No expiration deadline leads to losing a lot of funds

gas

Cannot use `_burn` Function in Beedle.sol Contract

Apr '23

Blueberry Update

Blueberry Update

10.74 USDC • 1 total finding • Sherlock • 0xepley

#16

medium

getPrice() doesn't check If Arbitrum sequencer is down in Chainlink feeds

Mar '23

Asymmetry contest

Asymmetry contest

85.96 USDC • 4 total findings • Code4rena • 0xepley

#57

high

Staking, unstaking and rebalanceToWeight can be sandwiched (Mainly rETH deposit )

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

medium

No slippage protection on `stake()` in SafEth.sol

medium

Lack of deadline for uniswap AMM