https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

Avci

Security Researcher

Contact Me

High

5

Total

Medium

1

Solo

15

Total

$10.83K

Total Earnings

#521 All Time

22x

Payouts

gold

1x

1st Places

regular

4x

Top 10

regular

8x

Top 25

All

Sherlock

Code4rena

Dec '24

Tally ARB Staker

Tally ARB Staker

32.25 USDC • Sherlock • Avci

#31

Nov '24

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

19.17 USDC • Sherlock • Avci

#51

Jul '24

Velocimeter

Velocimeter

79.87 USDC • 2 total findings • Sherlock • Avci

#45

high

`addLiquidity()` function is called with lack of working deadline and slippage protection

high

Claimable gauge distributions are lost when `killGaugeTotally` is called

Mar '24

Axis Finance

Axis Finance

66.36 USDC • 1 total finding • Sherlock • Avci

#26

medium

curator can lead to DOS `purchase()` function

WOOFi Swap

WOOFi Swap

262.30 USDC • 1 total finding • Sherlock • Avci

#8

medium

the `woPrice_` bound check will ignored if Chainlink returns zero price

Feb '24

AI Arena

AI Arena

0.23 USDC • 1 total finding • Code4rena • Avci

#179

medium

DoS in `MergingPool::claimRewards` function and potential DoS in `RankedBattle::claimNRN` function if called after a significant amount of rounds passed.

Jan '24

Curves

Curves

0 USDC • 1 total finding • Code4rena • Avci

#137

high

Unauthorized Access to setCurves Function

Oct '23

Ethena Labs

Ethena Labs

4.52 USDC • Code4rena • Avci

#40

Aug '23

Tangible Caviar

Tangible Caviar

0 USDC • Code4rena • Avci

#88

Jul '23

Tokensoft

Tokensoft

274.65 USDC • 1 total finding • Sherlock • Avci

#9

medium

getVestedFraction missed to check If Arbitrum sequencer is down

Beam

Beam

134.48 USDC • Sherlock • Avci

#38

GFX Labs

GFX Labs

209.52 USDC • 1 total finding • Sherlock • Avci

#8

medium

getGasPrice() doesn't check Arbitrum l2 chainlink feed is active

Jun '23

RealWagmi

RealWagmi

142.24 USDC • 1 total finding • Sherlock • Avci

#15

medium

The deposit - withdraw - trade transaction lack of expiration timestamp check (DeadLine check)

DODO V3

DODO V3

247.33 USDC • 3 total findings • Sherlock • Avci

#18

medium

Using unsafe ERC20 methods can revert the transaction for some tokens.

medium

getPrice() function doesn't check If Arbitrum sequencer is down in Chainlink feeds.

medium

There is no slippage control for trading functions at all

Mar '23

Gitcoin

Gitcoin

231.51 USDC • Sherlock • Avci

#20

Bond Protocol Update

Bond Protocol Update

8,620.68 USDC • 1 total finding • Sherlock • Avci

gold

medium

_validateAndGetPrice() doesn't check If Arbitrum sequencer is down in Chainlink feeds

Feb '23

Blueberry

Blueberry

100.83 USDC • 2 total findings • Sherlock • Avci

#31

medium

Oracle data feed has no check for round fullness

medium

wrong calculation in logic of the Lend function

Jan '23

Cooler

Cooler

274.09 USDC • 2 total findings • Sherlock • Avci

#12

high

in cooler.sol.rescind there is risk of funds to be lost

high

if transfer fails in repaying loan will be deleted

Dec '22

Tigris Trade contest

Tigris Trade contest

13.76 USDC • 1 total finding • Code4rena • Avci

#61

medium

`_handleDeposit` and `_handleWithdraw` do not account for tokens with decimals higher than 18

Aug '22

Sentiment

Sentiment

3.50 USDC • 1 total finding • Sherlock • Avci

#26

medium

contract should check the responses from chainlink aggregator

Jul '22

Swivel v3 contest

Swivel v3 contest

69.98 USDC • Code4rena • Avci

#49

Fractional v2 contest

Fractional v2 contest

38.87 USDC • 1 total finding • Code4rena • Avci

#96

medium

Use of `payable.transfer()` may lock user funds