Banner
https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/09f2b89f-6098-46aa-89d4-4e5e9781bf67.JPG

AuditorPraise

Graduate Judging Apprentice

Graduate Judging Apprentice

Contact Me

High

12

Total

Medium

1

Solo

21

Total

$6.19K

Total Earnings

#688 All Time

31x

Payouts

regular

7x

Top 10

regular

15x

Top 25

regular

27x

Top 50

All

Sherlock

Cantina

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

6.26 USDC • Sherlock • AuditorPraise

#57

Feb '25

Usual Labs

Usual Labs

77.27 USDC • Sherlock • AuditorPraise

#34

Yieldoor

Yieldoor

13.80 USDC • 1 total finding • Sherlock • AuditorPraise

#26

high

minBorrow check in `Leverager._checkWithinlimits()` should be done on borrowedAmount instead

Jan '25

Peapods

Peapods

130.12 USDC • 1 total finding • Sherlock • AuditorPraise

#24

medium

hardcoded V3_POS_MGR address won't be the same on every chain

Plaza Finance

Plaza Finance

0.87 USDC • 1 total finding • Sherlock • AuditorPraise

#97

medium

Auctions can always be gamed to end in FAILED_POOL_SALE_LIMIT state

Aave v3.3

Aave v3.3

18.67 USDC • Sherlock • AuditorPraise

#99

Dec '24

Tally ARB Staker

Tally ARB Staker

6.81 USDC • Sherlock • AuditorPraise

#38

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

23.10 OP • 2 total findings • Sherlock • AuditorPraise

#42

high

no method to withdraw interest gained from liquidations. They're forever stuck in the contract.

high

user being liquidated can prevent type1 liquidations if `liqAmountToGetFromOtherChain == 0` by causing unexpected reverts

Oct '24

AXION

AXION

50.94 USDC • 1 total finding • Sherlock • AuditorPraise

#12

medium

non of the contracts are ERC1504 compliant

Sep '24

Flayer

Flayer

298.22 USDC • 1 total finding • Sherlock • AuditorPraise

#37

high

Usage of price from slot0 in `UniswapImplementation.beforeSwap()` makes swap result easily manipulatable

Aug '24

Rumpel Point Tokenization Protocol

Rumpel Point Tokenization Protocol

91.48 USDC • Sherlock • AuditorPraise

#13

Winnables Raffles

Winnables Raffles

1.80 USDC • 1 total finding • Sherlock • AuditorPraise

#37

high

in `winnablesTicketManager.refundPlayers()` refunded eth is not deducted from `_lockedETH`.

Jul '24

MakerDAO Endgame

MakerDAO Endgame

290.89 USDC • Sherlock • AuditorPraise

#84

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

28.42 USDC • 3 total findings • Sherlock • AuditorPraise

#50

high

reverts in `Voter.vote()` due to wrong check in `BribeRewarder._modify()` [DOS]

medium

MasterChefV2.sol and bribeRewarder.sol will have accounting issues with Fee-On-Transfer Tokens

medium

A check in `MlumStaking.harvestPositionsTo()` makes approved users unable to harvest position for tokenId owner

Jun '24

Pegasus

Pegasus

250 USDC • Cantina • AuditorPraise

#11

May '24

PoolTogether: The Prize Layer for DeFi

PoolTogether: The Prize Layer for DeFi

336.33 USDC • 1 total finding • Sherlock • AuditorPraise

#16

medium

witnet doesn't support avalanche chain

Apr '24

Teller Finance

Teller Finance

502.20 USDC • 4 total findings • Sherlock • AuditorPraise

#10

high

lenders who claimed loan nfts won't be able to claim collateral for defaulted loans

high

`lenderCommitmentGroup_smart.liquidateDefaultedLoanWithIncentive()` will not give collateral to caller

high

using slot0 makes immediate pair price manipulatable, this is dangerous especially when principal token isn't token0

medium

`LenderCommitmentGroup_Smart.sol` inherits ownable upgradable but its never initialized

Feb '24

Jala Swap

Jala Swap

363.37 USDC • 1 total finding • Sherlock • AuditorPraise

#5

medium

`JalaPair` doesn't have a permit function, this will cause reverts in some functions in `JalaRouter02`

curvance

curvance

185.62 USDC • 1 total finding • Cantina • AuditorPraise

#41

medium

Finding not yet public.

Tapioca

Tapioca

906.10 USDC • 1 total finding • Sherlock • AuditorPraise

#10

medium

WETH was never set in baseLeverageExecutor.sol

Rio Network

Rio Network

5.57 USDC • 1 total finding • Sherlock • AuditorPraise

#31

high

`RioLRTWithdrawalQueue.settleEpochFromEigenLayer()` will lock `queuedWithdrawals`

Napier

Napier

456.67 USDC • 1 total finding • Sherlock • AuditorPraise

#7

medium

`stakeAmount` being 0 in BaseLSTAdapter.prefundedDeposits will cause reverts

opal-contracts

opal-contracts

1,210.95 USDC • 5 total findings • Cantina • AuditorPraise

#11

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jan '24

Arcadia

Arcadia

36.24 USDC • 1 total finding • Sherlock • AuditorPraise

#8

medium

There's a discrepancy between how the external stargate staking contract and AbstractStakingAM calculates `pending rewards` and `lastRewardPosition`

incentive-contracts

incentive-contracts

30.12 USDC • 1 total finding • Cantina • AuditorPraise

#33

medium

Finding not yet public.

Notional Update #5

Notional Update #5

227.98 USDC • 1 total finding • Sherlock • AuditorPraise

#8

medium

use SafeTransfer() instead of transfer() in SecondaryRewarder.reward().

Dec '23

Footium Update

Footium Update

14.58 USDC • Sherlock • AuditorPraise

#26

Olympus RBS 2.0

Olympus RBS 2.0

32.55 USDC • 1 total finding • Sherlock • AuditorPraise

#17

medium

`BalancerPoolTokenPrice.getWeightedPoolTokenPrice()` wrongly assumes that all weighted pools use `totalSupply`

Nov '23

Notional Update #4

Notional Update #4

237.52 USDC • 1 total finding • Sherlock • AuditorPraise

#7

medium

missing payable keyword on `TradingModule.executeTrade()` and `TradingModule.executeTradeWithDynamicSlippage()`, will cause VAULTS to be unable to execute trades on external exchanges via the trading module whenever ETH is the sell Token

Oct '23

Real Wagmi #2

Real Wagmi #2

257.41 USDC • 1 total finding • Sherlock • AuditorPraise

#14

high

old borrowing key is used instead of `newBorrowingKey` when adding old loans to the newBorrowing in LiquidityBorrowingManager.takeOverDebt()

Jul '23

Tokemak

Tokemak

99.49 USDC • 1 total finding • Sherlock • AuditorPraise

#44

medium

LMPVaultRegistry.removeVault doesn’t remove vault from _vaultsByType mapping