https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

AllTooWell

Security Researcher

Contact Me

High

3

Total

Medium

4

Total

$2.40K

Total Earnings

#1162 All Time

6x

Payouts

regular

2x

Top 10

regular

2x

Top 25

regular

4x

Top 50

All

Sherlock

Apr '26

Clear Macro by Superfluid

Clear Macro by Superfluid

24.82 USDC • Sherlock • AllTooWell

#46

Jan '26

Flying Tulip

Flying Tulip

183.69 USDC • Sherlock • AllTooWell

#74

Aug '24

Winnables Raffles

Winnables Raffles

5.17 USDC • 2 total findings • Sherlock • AllTooWell

#31

high

Anyone can cancel a raffle before it is created upon receiving the raffleId message from ethereum

high

The refund didn't deduct the corresponding amount from _lockedETH when canceling raffle

Jul '24

MakerDAO Endgame

MakerDAO Endgame

688.51 USDC • Sherlock • AllTooWell

#66

Apr '24

Exactly Protocol

Exactly Protocol

402.05 USDC • 1 total finding • Sherlock • AllTooWell

#10

medium

The calculation of `released` in `config` function of `RewardsController` is wrong

Zivoe

Zivoe

1,094.13 USDC • 4 total findings • Sherlock • AllTooWell

#10

high

```claimRewards(true)``` in ```OCC_Convex_A``` and ```OCC_Convex_C``` will always revert because of wrong integration about extra rewards in convex

medium

If ```Convex``` admin shut down the system or the integrated pool, can't deploy capital into ```convex``` and can't get rewards

medium

```pushToLockerMulti``` in ```OCL_ZVE``` will be DOS in most cases because of asserting 0 allowance after adding liquidity

medium

```forwardYield``` in ```OCL_ZVE``` can be manipulated to not forwarding yield by flash swap