https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/bd020b28-e0cc-4c68-96f5-1302080818fd.jpeg

Artur

Security Researcher

Contact Me

High

20

Total

Medium

13

Total

$1.81K

Total Earnings

#1122 All Time

17x

Payouts

bronze

2x

3rd Places

regular

6x

Top 10

regular

10x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Jul '25

succinct-network

succinct-network

311.87 USDC • 2 total findings • Cantina • Artur

#16

high

Finding not yet public.

medium

Finding not yet public.

Jun '25

Superfluid Locker System

Superfluid Locker System

451.00 USDC • 1 total finding • Sherlock • Artur

#6

medium

Anyone can unlock instantly and dodge fees whenever no one is staking in the Tax pool

May '25

LayerEdge - Staking

LayerEdge - Staking

7.19 USDC • 1 total finding • Sherlock • Artur

#7

medium

Users can get locked out of the protocol due to gas limit issues

alchemix-v3

alchemix-v3

76.1 USDC • 8 total findings • Cantina • Iki-gai

#64

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

Aegis.im YUSD

Aegis.im YUSD

139.83 OP • 1 total finding • Sherlock • Ikigai

bronze

medium

User Can Perpetually Deny Redeems by Cycling Mint and Redeem Requests with Zero Fees

Mar '25

Crestal Network

Crestal Network

0.01 USDC • 1 total finding • Sherlock • Artur

#12

high

Unauthorized Token Transfer via payWithERC20

Symmio, Staking and Vesting

Symmio, Staking and Vesting

68.35 USDC • 2 total findings • Sherlock • Artur

#10

high

Malicious user can grief staking rewards for legitimate stakers through frequent claiming

medium

Any user can grief reward rates by adding minimal rewards

Feb '25

Core Contracts

Core Contracts

3.69 usdc • 7 total findings • CodeHawks • arturtoros

#314

high

Incorrect Reward Claim Logic in FeeCollector::claimRewards Causes Denial of Service

high

Treasury Balance Tracking Bypass in FeeCollector

high

Ineffective Time-Weighted Average Implementation in Fee Distribution

medium

Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations

medium

Multiple Token Management Lets Withdraw a Token Different than Deposited Token

low

`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types

low

Treasury's allocated funds not tracked during withdrawals leads to accounting issue where recepient can receive more than allocated funds.

Jan '25

Plaza Finance

Plaza Finance

0.18 USDC • 1 total finding • Sherlock • Artur

#100

high

Auction cannot complete successfully due to period mismatch between Pool and BondToken contracts

Dec '24

SecondSwap

SecondSwap

6.98 USDC • 3 total findings • Code4rena • macart224

#46

high

`SecondSwap_Marketplace` vesting listing order affects how much the vesting buyers can claim at a given step

medium

Incorrect referral fee calculations

medium

Rounding error in stepDuration calculations.

Lambo.win

Lambo.win

0.3 USDC • 2 total findings • Code4rena • macart224

#35

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

medium

Since the cost of launching a new pool is minimal, an attacker can maliciously consume VirtualTokens.

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

0.38 USDC • 1 total finding • Sherlock • Artur

#33

high

# Double Counting of Fees in ReputationMarket Will Lead to Fund Loss

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

146.01 USDC • Sherlock • Artur

#22

Telcoin Update #2

Telcoin Update #2

205.07 USDC • Sherlock • Artur

#10

Oct '24

Gamma Brevis Rewarder

Gamma Brevis Rewarder

131.06 OP • 1 total finding • Sherlock • Artur

bronze

high

Claim Restriction Prevents Users from Claiming Multiple Epochs

Sep '24

Royco Protocol

Royco Protocol

253.13 USDC • 3 total findings • Cantina • Ikigai

#28

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Jul '24

Basin

Basin

8.44 USDC • 1 total finding • Code4rena • macart224

#11

high

Incorrectly assigned `decimal1` parameter upon decoding