https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

4rdiii

Security Researcher

Contact Me

High

8

Total

Medium

7

Total

$54.00

Total Earnings

#2088 All Time

14x

Payouts

regular

3x

Top 25

regular

7x

Top 50

All

Sherlock

Code4rena

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • 4rdiii

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

Dec '24

SecondSwap

SecondSwap

4.14 USDC • 1 total finding • Code4rena • 4rdiii

#56

high

`SecondSwap_Marketplace` vesting listing order affects how much the vesting buyers can claim at a given step

Lambo.win

Lambo.win

0 USDC • 1 total finding • Code4rena • 4rdiii

#36

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

Nov '24

Concrete

Concrete

10.24 USDC • Code4rena • 4rdiii

#92

Aug '24

Chakra

Chakra

0.03 USDT • 1 total finding • Code4rena • 4rdiii

#66

high

SettlementSignatureVerifier is missing check for duplicate validator signatures

Jul '24

TraitForge

TraitForge

0.05 USDC • 2 total findings • Code4rena • 4rdiii

#85

medium

`Golden God` Tokens can be minted twice per generation

medium

Discrepancy between nfts minted, price of nft when a generation changes & position of `_incrementGeneration()` inside `_mintInternal()` & `_mintNewEntity()`

Karak Restaking

Karak Restaking

0 USDC • Code4rena • 4rdiii

#16

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

0.08 USDC • 1 total finding • Sherlock • 4rdiii

#64

medium

BribeRewarder::fundAndBribe will always revert if fee on transfer tokens are used as rewarder main token

Jun '24

Vultisig

Vultisig

6.78 USDC • 1 total finding • Code4rena • 4rdiii

#31

high

Vultisig whitelisting can be bypassed by anyone

May '24

Munchables

Munchables

0 USDC • 1 total finding • Code4rena • 4rdiii

#17

high

Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens

Elfi

Elfi

3.14 USDC • 1 total finding • Sherlock • 4rdiii

#29

medium

[H-1] Incorrect `lossFee` Calculation in `GasProcess::processExecutionFee` to Resulting in Keeper's Financial Loss

Apr '24

NOYA

NOYA

0.18 USDC + NOYA stars • 1 total finding • Code4rena • 4rdiii

#121

medium

Incorrect modifier condition

TITLES Publishing Protocol

TITLES Publishing Protocol

26.47 USDC • 2 total findings • Sherlock • 4rdiii

#37

high

[M2] `Edition::mintBatch` will revert if you try to mint more than 1 NFTs

medium

[M-1] `TitlesGraph::_setAcknowledged` does not change the state variable correctly

DYAD

DYAD

3.84 USDC • 2 total findings • Code4rena • 4rdiii

#108

high

Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral

high

Unable to withdraw Kerosene from `vaultmanagerv2::withdraw` as it expects a `vault.oracle()` method which is missing in Kerosene vaults