Security Researcher
High
Total
Medium
Total Earnings
#605 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Sep '22
28.07 USDC • Code4rena • 0xf15ers
#67
18.87 USDC • Code4rena • 0xf15ers
#76
Aug '22
3.50 USDC • 1 total finding • Sherlock • 0xf15ers
#26
medium
Oracle `latestRoundData` might return stale or incorrect results
77.72 USDC • 1 total finding • Code4rena • 0xf15ers
#35
ERROR IN UPDATING **_checkpoint** IN THE **increaseUnlockTime** FUNCTION
40.62 USDC • Code4rena • 0xf15ers
#68
Jul '22
56.13 USDC • Code4rena • 0xf15ers
#43
167.73 USDC • Code4rena • 0xf15ers
#64
83.57 USDC • Code4rena • 0xf15ers
#62
62.31 USDC • Code4rena • 0xf15ers
#85
146.38 USDC • 2 total findings • Code4rena • 0xf15ers
#34
high
ORACLE DATA FEED CAN BE OUTDATED YET USED ANYWAYS WHICH WILL IMPACT ON PAYMENT LOGIC
Use a safe transfer helper library for ERC20 transfers
Jun '22
83.79 USDC • Code4rena • 0xf15ers
#50
46.17 USDC • Code4rena • 0xf15ers
80.04 USDC • Code4rena • 0xf15ers
#52
126.4 USDC • Code4rena • 0xf15ers
#51
104.6 USDC • Code4rena • 0xf15ers
#14
505.47 USDC • 3 total findings • Code4rena • 0xf15ers
#22
Accumulated ETH fees of InfinityExchange cannot be retrieved
`_transferNFTs()` succeeds even if no transfer is performed
InfinityExchange computes gas refunds in a way where the first order's buyer pays less than the later ones
4,445.77 USDC • 3 total findings • Code4rena • 0xf15ers
#5
WETH.allowance() returns wrong result.
Comptroller uses the wrong address for the WETH contract
Incorrect amount taken
283.8 USDC • Code4rena • 0xf15ers
#29
159.11 USDC • Code4rena • 0xf15ers
#20
May '22
171.81 USDC • Code4rena • 0xf15ers
152.48 USDT • Code4rena • 0xf15ers
#47
125.19 USDC • 1 total finding • Code4rena • 0xf15ers
#45
Malicious user can populate `rewards` array with tokens of their interest reaching limits of `MAX_REWARD_TOKENS`
82.94 USDC • Code4rena • 0xf15ers
86.25 USDC • 1 total finding • Code4rena • 0xf15ers
#27
The check for value transfer success is made after the return statement in _withdrawFromYieldPool of LidoVault
234.74 USDC • Code4rena • 0xf15ers
124.84 USDC • 2 total findings • Code4rena • 0xf15ers
Owner can modify the feeRate on existing vaults and steal the strike value on exercise
User's may accidentally overpay in `buyOption()` and the excess will be paid to the vault creator
276.93 USDT • Code4rena • 0xf15ers
#39
91.84 DAI • Code4rena • 0xf15ers
#42
451.07 DAI • 1 total finding • Code4rena • 0xf15ers
#17
DoS: Attacker may significantly increase the cost of `withdrawExcessRewards()` by creating a significant number of excess receipts
75.66 USDC • Code4rena • 0xf15ers
45.77 USDC • Code4rena • 0xf15ers
Apr '22
197.13 USDC • Code4rena • 0xf15ers
#16
657.08 MIM • 1 total finding • Code4rena • 0xf15ers
The return value `success` of the get function of the INFTOracle interface is not checked