https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/f3dc50c7-66b9-4389-a53c-200889d394c6.jpg

0xspryon

Security Researcher

I find bugs in web3 protocols.

Contact Me

High

4

Total

Medium

6

Total

$614.00

Total Earnings

#1443 All Time

8x

Payouts

regular

2x

Top 25

regular

5x

Top 50

All

Code4rena

CodeHawks

Feb '25

Core Contracts

Core Contracts

2.18 usdc • 4 total findings • CodeHawks • 0xspryon

#333

high

Users Can Overwrite Existing Locks in veRAACToken Resulting in Permanent Loss of Funds

high

Attackers can double voting power and veToken amount by locking and increasing

medium

Wrong access control in `RAACToken::setFeeCollector`, `RAACToken::setSwapTaxRate`, `RAACToken::setBurnTaxRate`

low

Limited veRaac Token Supply Triggers DoS, Hampering Proper Governance Participation.

Dec '24

Alchemix Transmuter

Alchemix Transmuter

0.00 op • 1 total finding • CodeHawks • 0xspryon

#31

low

Old router retains token allowance after update

Aug '24

Tadle

Tadle

0.00 USDC • 1 total finding • CodeHawks • 0xspryon

#175

high

Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function

Jul '24

LoopFi

LoopFi

0.06 USDC • 1 total finding • Code4rena • 0xspryon

#57

medium

`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`

TempleGold

TempleGold

31.81 USDC • 2 total findings • CodeHawks • 0xspryon

#32

high

Incompatibility with Multisig Wallets in `TempleGold::send` Function

low

Incosistent message generation in TempleTeleporter.quote() and TempleTeleporter.teleport() results in inaccurate required fee calculation by TempleTeleporter.quote()

May '24

Sablier

Sablier

279.35 USDC • 2 total findings • CodeHawks • 0xspryon

#17

low

Merkle Tree related contracts will be subject to Cross Chain Replay attacks

low

Stream sender is unable to cancel a stream with a pausable asset that is paused

Mar '24

Revert Lend

Revert Lend

140.43 USDC • 3 total findings • Code4rena • 0xspryon

#44

medium

Dangerous use of deadline parameter

medium

V3Oracle susceptible to price manipulation

medium

V3Vault is not ERC-4626 compliant

Dec '23

The Standard

The Standard

161.08 USDC • 1 total finding • CodeHawks • 0xspryon

#17

medium

Removing assets in the `TokenManager` leads to major issues