https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/de12baec-663e-47c4-b0f7-cfe75bbad80b.jpg

0xmuxyz

Security Researcher

fee75964d7

Contact Me

High

9

Total

Medium

24

Total

$3.58K

Total Earnings

#845 All Time

38x

Payouts

regular

7x

Top 25

regular

19x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

Oct '24

stakeup-bloomv2

stakeup-bloomv2

33.77 USDC • 2 total findings • Cantina • 0xmuxyz

#76

medium

Finding not yet public.

medium

Finding not yet public.

Aug '24

Phi

Phi

17.25 USDC • 1 total finding • Code4rena • 0xmuxyz

#41

high

`shareBalance` bloating eventually blocks curator rewards distribution

Jul '24

Zaros Part 1

Zaros Part 1

138.54 USDC • 1 total finding • CodeHawks • 0xmuxyz

#42

high

`SettlementBranch._fillOrder` does not guarantee the collateral of a position is enough to pay the future liquidation fee.

MakerDAO Endgame

MakerDAO Endgame

44.42 USDC • Sherlock • 0xmuxyz

#110

Apr '24

NOYA

NOYA

7.57 USDC + NOYA stars • 4 total findings • Code4rena • 0xmuxyz

#100

high

`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`

medium

Attacker can increase the length of `withdrawQueue` by withdrawing 0 amount of tokens frequently

medium

Missing calls to `_updateTokenInRegistry` leads to incorrect state of tokens in registry

medium

`depositQueue.queue` in `AccountingManager` can be flooded causing a DoS

Mar '24

Axis Finance

Axis Finance

202.31 USDC • 1 total finding • Sherlock • 0xmuxyz

#20

medium

The TX of the AuctionHouse#`refundBid()` called by the bidders, who are not winner, would be DOSed

Jan '24

Salty.IO

Salty.IO

44.44 USDC • 1 total finding • Code4rena • 0xmuxyz

#93

medium

formPOL lacks slippage and deadline protection

Curves

Curves

3.82 USDC • Code4rena • 0xmuxyz

#111

incentive-contracts

incentive-contracts

550.85 USDC • 1 total finding • Cantina • 0xmuxyz

#20

high

Finding not yet public.

Dec '23

The Standard

The Standard

15.80 USDC • 2 total findings • CodeHawks • 0xmuxyz

#63

high

Looping over unbounded `pendingStakes` array can lead to permanent DoS and frozen funds

medium

Wrong Implementation of `LiquidationPool::empty` excludes holder with pending stakes when decreasing a position, resulting in exclusion from asset distribution

Oct '23

Steadefi

Steadefi

261.33 USDC • 2 total findings • CodeHawks • 0xmuxyz

#17

medium

A depositor of the GMXVault can bypass paying the fee when the depositor deposit into the GMXVault.

low

Unhandled DoS when access to Chainlik oracle is blocked

Sep '23

DittoETH

DittoETH

171.30 USDC • 3 total findings • CodeHawks • 0xmuxyz

#30

medium

Possible DOS on deposit(), withdraw() and unstake() for BridgeReth, leading to user loss of funds

medium

Lack of essential stale check in oracleCircuitBreaker()

low

User will lose collateral in the exact case `cRatio == minimumCR`

Aug '23

Dopex

Dopex

90.63 USDC • 1 total finding • Code4rena • 0xmuxyz

#83

medium

Missing slippage parameter on Uniswap `addLiquidity()` function

veRWA

veRWA

4.23 USDC • Code4rena • 0xmuxyz

#53

Tangible Caviar

Tangible Caviar

0.72 USDC • Code4rena • 0xmuxyz

#86

Good Entry

Good Entry

482.48 USDC • 1 total finding • Code4rena • 0xmuxyz

#18

high

Overflow can still happened when calculating `priceX8` inside `poolMatchesOracle` operation

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

3.22 USDC • 2 total findings • CodeHawks • 0xmuxyz

#178

high

Sandwich attack to steal all ERC-20 tokens in the Fees contract

gas

User can steal reward tokens if the Staking contract uses tokens with different decimals

CodeHawks Escrow Contract - Competition Details

CodeHawks Escrow Contract - Competition Details

0.00 USDC • 1 total finding • CodeHawks • 0xmuxyz

#96

low

Constructor of `Escrow` should make sure that `buyer`, `seller`, `arbiter` are different from each other.

Amphora Protocol

Amphora Protocol

9.43 USDC • Code4rena • 0xmuxyz

#23

Tokemak

Tokemak

7.81 USDC • 1 total finding • Sherlock • 0xmuxyz

#52

high

The `msg.value` of Native ETH (in the form of the `msg.value` of WETH) would not be tracked and just stuck in the LMPVaultRouter if a user deposit the `amount` of WETH (`vault.asset()`) and send the `msg.value` of Native ETH at the same time when the user call the LMPVaultRouterBase#`deposit()`

Jun '23

Hubble Exchange

Hubble Exchange

0.14 USDC • 1 total finding • Sherlock • 0xmuxyz

#30

medium

Lack of validation to check whether or not the return value would be a stale price data

Symmetrical

Symmetrical

175.30 USDC • 2 total findings • Sherlock • 0xmuxyz

#27

high

Lack of scaling the decimals precision in the AccountFacet#`depositAndAllocateForPartyB()`, which lead to a misaccounting

medium

A PartyB manager can not remove (revoke) a PartyB's address even if the PartyB's address is a malicious address

May '23

Footium

Footium

0.01 USDC • 1 total finding • Sherlock • 0xmuxyz

#32

medium

Lack of a refund logic of the excess fee, which lead to an unexpected result that the excess fee of the caller will be stuck forever in the FootiumAcademy contract

Apr '23

Teller

Teller

217.95 USDC • 1 total finding • Sherlock • 0xmuxyz

#25

medium

A borrower/lender or liquidator will fail to withdraw the collateral assets due to reaching a gas limit

Frankencoin

Frankencoin

22.6 USDC • Code4rena • 0xmuxyz

#66

Rubicon v2

Rubicon v2

0 USDC • 1 total finding • Code4rena • 0xmuxyz

#127

medium

Zero reward rate calculation impedes low-decimals token distributions

Mar '23

Gitcoin

Gitcoin

62.22 USDC • Sherlock • 0xmuxyz

#48

Asymmetry contest

Asymmetry contest

13.13 USDC • Code4rena • 0xmuxyz

#110

Y2K

Y2K

253.03 USDC • 1 total finding • Sherlock • 0xmuxyz

#41

medium

A malicious user can create and enlist too many deposit queues at row cost, which lead to reverting the transaction because of reaching the block gas limit

Feb '23

Ethos Reserve contest

Ethos Reserve contest

61.26 USDC • Code4rena • 0xmuxyz

#33

OpenQ

OpenQ

48.24 USDC • 1 total finding • Sherlock • 0xmuxyz

#39

medium

A transaction of calling the the DepositManagerV1# `fundBountyNFT()` may be reverted despite the actual number of NFTs deposited (funded) has not reached the `nftDepositLimit` yet.

Jan '23

Popcorn contest

Popcorn contest

146.06 USDC • 2 total findings • Code4rena • 0xmuxyz

#62

medium

Vault fees can be set to anything when initilizing

medium

Malicious Users Can Drain The Assets Of Vault. (Due to not being ERC4626 Complaint)

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

17.2 USDC • Code4rena • 0xmuxyz

#74

Dec '22

Caviar contest

Caviar contest

184.33 USDC • 1 total finding • Code4rena • 0xmuxyz

#28

medium

Price will not always be 18 decimals, as expected and outlined in the comments

Tigris Trade contest

Tigris Trade contest

165.62 USDC • 1 total finding • Code4rena • 0xmuxyz

#42

medium

`safeTransferMany()` doesn't actually use safe transfer

Nov '22

Bull v Bear

Bull v Bear

39.76 USDC • 1 total finding • Sherlock • 0xmuxyz

#15

medium

Lack of check whether the caller of `withdrawToken()` function is the Bull or not

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

52.03 USDC • Code4rena • 0xmuxyz

#52

Sep '22

Y2k Finance contest

Y2k Finance contest

36.62 USDC • Code4rena • 0xmuxyz

#51