https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/475537c2-566e-4d29-ac84-a016d4b9fb33.jpg

Afriaudit

Security Researcher

Medicine ➡️ Web 3 security. Smart contract security researcher............ Aspiring 10,000X security researcher

Contact Me

High

8

Total

Medium

12

Total

$17.37K

Total Earnings

#380 All Time

19x

Payouts

silver

1x

2nd Places

regular

10x

Top 10

regular

15x

Top 25

All

Sherlock

Code4rena

Apr '25

Cabal Liquid Staking Token

Cabal Liquid Staking Token

249.98 USDC • Code4rena • Afriauditor

#8

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

8.89 USDC • 1 total finding • Sherlock • Afriaudit

#17

medium

Inability to Add Liquidity When More Than Half of Initial Tokens Have Unlocked Due to redundant Check

Feb '25

Usual Labs

Usual Labs

3,773.20 USDC • Sherlock • Afriaudit

#5

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • Afriauditor

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

Beraborrow

Beraborrow

4,503.87 USDC • Sherlock • Afriaudit

#6

Findings not publicly available for private contests.

FlatMoney v2 Update

FlatMoney v2 Update

62.04 USDC • Sherlock • Afriaudit

#13

Findings not publicly available for private contests.

Dec '24

Numa

Numa

987.97 USDC • 1 total finding • Sherlock • Afriaudit

#9

medium

Excessive Buy PID Adjustment Due to Double Fee Application in `buyNoMax`

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

0.00 OP • 1 total finding • Sherlock • Afriaudit

#66

high

Non-Unique Order ID Generation in `generateOrderId` Function

Oct '24

Avantis v1.5: Cross-Asset Leverage

Avantis v1.5: Cross-Asset Leverage

2,228.21 OP • Sherlock • Afriaudit

#9

Findings not publicly available for private contests.

Aug '24

Midas - Instant Minter/Redeemer

Midas - Instant Minter/Redeemer

607.37 USDC • 1 total finding • Sherlock • Afriaudit

#8

medium

Allowance Not Decreased in `approveRequest()` Function in `DepositVault` and` RedemptionVaul` Contracts

Winnables Raffles

Winnables Raffles

2.56 USDC • 2 total findings • Sherlock • Afriaudit

#36

high

Indefinite Locking of Future ETH Due to `_lockedETH` Not Updated in `refundPlayers` Function in `WinnablesTicketManager` Contract

medium

Inconsistent Role Management in `_setRole` Function Due to Ignored `status` Parameter

Jul '24

LoopFi

LoopFi

807.59 USDC • 4 total findings • Code4rena • Afriauditor

#20

high

Debt position interest is compounded while pool interest is simple causing inconsistency b/w `expectedLiquidity_` and `availableLiquidity_`

medium

`PoolV3#repayCreditAccount()` use incorrect share converting function to calculate profit and loss

medium

WhenNotPaused modifier in the CDPVault can be bypassed by users

medium

Malicious actor can abuse the minimum shares check in `StakingLPEth` and cause DoS or locked funds for the last user that withdraws

Deepr

Deepr

1,265.22 USDC • Sherlock • Afriaudit

#4

Findings not publicly available for private contests.

May '24

Midas

Midas

988.96 USDC • 1 total finding • Sherlock • Afriaudit

silver

medium

REDEMPTION_VAULT_ADMIN_ROLE and DEPOSIT_VAULT_ADMIN_ROLE allows Pausing and Unpausing of `DepositVault` and `RedemptionVault` Contract

Apr '24

Teller Finance

Teller Finance

44.94 USDC • 1 total finding • Sherlock • Afriaudit

#28

medium

Missing Initialization of OwnableUpgradeable in `LenderCommitmentGroup_Smart` Contract

Zivoe

Zivoe

50.15 USDC • 4 total findings • Sherlock • Afriaudit

#46

high

Malicious actor can reduce reward rate potentially preventing users from ever getting full reward in the ZivoeRewards contract.

high

`_totalSupply` parameter wrongly updated in `revokeVestingSchedule` function causing loss of reward for users with vesting schedule in `ZivoeRewardsVesting`

high

`_writeCheckpoint` wrongly updated in the `revokeVestingSchedule` function causing incorrect management of voting power.

medium

The protocol will encounter pesisitent reverting when interacting with Uniswap due to failure to reduce the allowance left before the assert statement ensuring zero allowance

Mar '24

vVv Vesting & Staking

vVv Vesting & Staking

194.72 USDC • Sherlock • Afriaudit

#12

Amphor

Amphor

679.98 USDC • 1 total finding • Sherlock • Afriaudit

#7

high

Receiver will be unable to claim redeem when address of `owner` and `receiver` are different in `requestredeem`

PoolTogether

PoolTogether

915.44 USDC • 2 total findings • Code4rena • Afriauditor

#5

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

medium

`PrizeVault.maxDeposit()` doesn't take into account produced fees