https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/b240ea1b-12ca-4c29-bcdb-655224a3492b.jpg

ArmedGoose

Security Researcher

Smart Contract Auditor 64fbec45e5

Contact Me

High

5

Total

Medium

11

Total

$10.23K

Total Earnings

#544 All Time

10x

Payouts

silver

1x

2nd Places

regular

4x

Top 10

regular

6x

Top 25

All

Sherlock

Code4rena

Jan '25

IOTA

IOTA

Collaborative Audit • Sherlock • ArmedGoose

Apr '24

DYAD

DYAD

463.51 USDC • 4 total findings • Code4rena • ArmedGoose

#23

high

Inability to perform partial liquidations allows huge positions to accrue bad debt in the system

high

Attacker Can Frontruns User's Withdrawals To Make Them Reverts Without Costs

medium

Attacker can frontrun to prevent vaults from being removed from the dNFT owner's position

medium

No incentive to liquidate when CR <= 1 as asset received < dyad burned

Feb '24

Spectra

Spectra

6,794.23 USDC • 1 total finding • Code4rena • ArmedGoose

silver

medium

All yield generated in the IBT vault can be drained by performing a vault deflation attack using the flash loan functionality of the Principal Token contract

Dec '23

Revolution Protocol

Revolution Protocol

881.32 USDC • 2 total findings • Code4rena • ArmedGoose

#9

high

````VerbsToken.tokenURI()```` is vulnerable to JSON injection attacks

medium

Bidder can use donations to get VerbsToken from auction that already ended.

Oct '23

Real Wagmi #2

Real Wagmi #2

781.52 USDC • 2 total findings • Sherlock • ArmedGoose

#6

high

Malicious liquidity provider may burn their LP NFT to make liquidations impossible and cause protocol to incur bad debt

medium

If the LPer becomes blacklisted for particular holdTokens like USDC,USDT, then liquidation of related position will not be possible

Sep '23

Venus Prime

Venus Prime

21.61 USDC • Code4rena • ArmedGoose

#35

Allo V2

Allo V2

185.28 USDC • 2 total findings • Sherlock • ArmedGoose

#35

medium

In QVStrategy, regular member can exclude some recipient candidates by resetting the `Accepted` status back to `Pending`

medium

Protocol will not work properly with fee-on-transfer tokens

Aug '23

Dopex

Dopex

109.8 USDC • 1 total finding • Code4rena • ArmedGoose

#72

medium

Missing slippage parameter on Uniswap `addLiquidity()` function

Jul '23

PoolTogether

PoolTogether

15.92 USDC • Code4rena • ArmedGoose

#66

Dinari

Dinari

61.94 USDC • 1 total finding • Sherlock • ArmedGoose

#12

medium

Cancelled orders are refunded to recipients instead of payers, some users might lose funds

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

915.88 USDC • 3 total findings • Code4rena • ArmedGoose

#9

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`

medium

When `rewardToken` is erc1155/erc777,an attacker can reenter and cause funds to be stuck in the contract forever

medium

DOS risk if enough tokens are minted in Quest.claim can lead, at least, to transaction fee lost