Security Researcher
Smart contract security researcher | Warden at @code4rena
High
Total
Medium
Total Earnings
#905 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
CodeHawks
Feb '25
523.48 USDC • Sherlock • 0xloscar01
#19
0 USDC • 1 total finding • Code4rena • 0xloscar01
#10
medium
Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector
Dec '24
223.79 USDC • Sherlock • 0xloscar01
#13
5.38 USDC • 2 total findings • Code4rena • 0xloscar01
#48
high
`SecondSwap_Marketplace` vesting listing order affects how much the vesting buyers can claim at a given step
Users can claim more that their actual allotment
3.99 OP • 1 total finding • Sherlock • 0xloscar01
#37
`Bracket::performUpkeep` will revert due to residual allowance and the usage of `safeApprove`
Nov '24
9.58 USDC • 2 total findings • Sherlock • 0xloscar01
#50
Attacker will prevent lenders from canceling lend orders and block non-perpetual lend orders matching.
DebitaIncentives::updateFunds will exit prematurely and not update whitelisted pairs causing loss of funds to lenders and borrowers
Sep '24
23.07 USDC • 1 total finding • Sherlock • 0xloscar01
#22
Incentives `clawback` and `drawRaffle` functions are inaccessible to all parties, including Boost creators and Boost owners.
Aug '24
0.27 USDC • 1 total finding • CodeHawks • 0xloscar01
`FjordAuction` incorrect `block.timestamp` check allows users to bid after calling `auctionEnd` to claim more tokens than they should
0.00 USDC • 1 total finding • CodeHawks • 0xloscar01
#177
TokenManager - Unlimited withdraw
May '24
656.97 USDC • 1 total finding • Sherlock • 0xloscar01
#4
`MidasAccessControl` allows blacklisted users to bypass `mTBILL` ban by renouncing the `BLACKLISTED_ROLE`
0.01 USDC • 1 total finding • Code4rena • 0xloscar01
#16
Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens
Apr '24
0.02 USDC • 1 total finding • Code4rena • 0xloscar01
#114
Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral
Mar '24
17.32 USDC • 1 total finding • Code4rena • 0xloscar01
#67
Owner of a position can prevent liquidation due to the 'onERC721Received' callback
Feb '24
255.08 USDC • 1 total finding • Sherlock • 0xloscar01
#6
`JalaPair` functions calling `_update` will revert when `price0CumulativeLast` or `price1CumulativeLast` overflows
104.73 USDC • 1 total finding • Code4rena • 0xloscar01
#23
`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.
Dec '23
0.07 USDC • 1 total finding • CodeHawks • 0xloscar01
#102
Rewards can be drained because of lack of access control
Nov '23
1,111.11 USDC • 1 total finding • Code4rena • 0xloscar01
Partial transfers are still possible, leading to incorrect storage updates, and the calculated account premiums will be significantly different from what they should be