https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

Aymen0909

Security Researcher

Contact Me

High

65

Total

Medium

79

Total

$38.70K

Total Earnings

#222 All Time

119x

Payouts

regular

8x

Top 10

regular

49x

Top 25

regular

88x

Top 50

All

Sherlock

Code4rena

Jan '25

Plaza Finance

Plaza Finance

22.30 USDC • 5 total findings • Sherlock • Aymen0909

#65

high

Incorrect `currentPeriod` in `transferReserveToAuction` Leads to Auction Funds Being Stuck

medium

Attacker can force auctions to fail preventing bond holders from getting rewards

medium

Risk of DoS During Auction Bidding Due to USDC Blacklisted Bidders

medium

Chainlink Has No Price Feed for WSTETH/USD on Base, WSTETH Cannot Be Used as a Reserve Token

medium

Coupon Shares are allocated even if auction fails, resulting in users unable to claim rewards

Dec '24

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

30.99 OP • 4 total findings • Sherlock • Aymen0909

#38

high

`BorrowLiquidation` contract will incorrectly send the remaining ETH to the borrower after liquidation

high

Anyone can inflate `downsideProtected` causing a DOS of deposit/withdraw in `CDS`

high

Owner will be unable to withdraw interest from treasury under certain conditions

medium

`BorrowLiquidation::liquidationType2` calculates the amount of sETH to short incorrectly when liquidating with Synthetix

Sep '24

Boost Core Incentive Protocol

Boost Core Incentive Protocol

23.07 USDC • 1 total finding • Sherlock • Aymen0909

#22

high

`BoostCore` will be unable to invoke incentives `clawback` functions

Flayer

Flayer

54.37 USDC • 2 total findings • Sherlock • Aymen0909

#60

high

Users will not be able to reclaim voting tokens after a shutdown is cancelled

medium

User can stop a shutdown execution by creating a new listing which will force all voters to wait a long period before getting their payout

Jul '24

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

49.58 USDC • 4 total findings • Sherlock • Aymen0909

#37

high

`BribeRewarder.deposit` Will Always Revert, Blocking the Voting Mechanism

high

`Voter.vote` Allows Users to Vote with Expired Locks, Introducing Voting Manipulation Risks

high

Unclaimed Bribe Rewards Remain Stuck in `BribeRewarder`

medium

Incorrect Check in `_requireOnlyOperatorOrOwnerOf` Allows Unauthorized Access

Velocimeter

Velocimeter

211.18 USDC • 1 total finding • Sherlock • Aymen0909

#37

high

Attacker could increase users lock time by exercising small amount with `exerciseLp`

Jun '24

Vultisig

Vultisig

10.42 USDC • 1 total finding • Code4rena • Aymen0909

#30

medium

Transfer of ILOPool NFT token to different account allows for users to bypass the pool's `maxCapPerUser` invariant

May '24

Olas

Olas

1,481.24 USDC • 1 total finding • Code4rena • Aymen0909

#8

high

`pointsSum.slope` Not Updated After Nominee Removal and Votes Revocation

Apr '24

Renzo

Renzo

337.24 USDC • 4 total findings • Code4rena • Aymen0909

#26

high

Incorrect withdraw queue balance in TVL calculation

high

DOS of `completeQueuedWithdrawal` when ERC20 buffer is filled

medium

Deposits will always revert if the amount being deposited is less than the bufferToFill value

medium

Withdrawals and Claims are meant to be pausable, but it is not possible in practice

NOYA

NOYA

28.99 USDC + NOYA stars • 4 total findings • Code4rena • Aymen0909

#71

high

`AccountingManager::resetMiddle` will not behave as expected

high

`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`

medium

The total deposit amount limit in `AccountingManager.sol` can be bypassed

medium

Incorrect modifier condition

Zivoe

Zivoe

8.23 USDC • 1 total finding • Sherlock • Aymen0909

#53

high

`ZivoeRewardsVesting::revokeVestingSchedule` incorrectly decreases the total staking supply `_totalSupply`

Panoptic

Panoptic

3,564.62 USDC • 2 total findings • Code4rena • Aymen0909

#7

high

`SettleLongPremium` is incorrectly implemented: premium should be deducted instead of added

medium

Wrong leg `chunkKey` calculation in `haircutPremia` function

Mar '24

Ondo Finance

Ondo Finance

8.28 USDC • Code4rena • Aymen0909

#17

Acala

Acala

903.86 USDC • 1 total finding • Code4rena • Aymen0909

#9

medium

Unbond_instant removes incorrect amount of shares

Axis Finance

Axis Finance

1,404.77 USDC • 5 total findings • Sherlock • Aymen0909

#11

high

Gas Mode Not Set to `Claimable` in `BlastGas` Contract

high

Some ERC20 don't allow 0 amount transfers which could result in Seller being unable to claim prefunded Base token capacity after `EMPAM` Auction settles without being filled

medium

Batch auction settlement will be impossible if partially filled bidder or the curator get blacklisted in the base or quote tokens

medium

Inability for Seller to Claim Remaining Capacity after Prefunded Atomic Auction `FPAM` Concludes

medium

Some Bidders might be unable to claim their payout if Base token derivative expiry is too close to auction expiry

Taiko

Taiko

2,181.75 USDC • 2 total findings • Code4rena • Aymen0909

#10

high

Users will never be able to withdraw their claimed airdrop fully in ERC20Airdrop2.sol contract

medium

retryMessage unable to handle edge cases.

Revert Lend

Revert Lend

2,883.87 USDC • 6 total findings • Code4rena • Aymen0909

#4

high

Risk of reentrancy `onERC721Received` function to manipulate collateral token configs shares

medium

dailyDebtIncreaseLimitLeft is not updated in liquidate().

medium

Repayments and liquidations can be forced to revert by an attacker that repays miniscule amount of shares

medium

V3Vault is not ERC-4626 compliant

medium

Wrong global lending limit check in `_deposit` function

medium

Users can lend and borrow above allowed limitations

PoolTogether

PoolTogether

171.96 USDC • 6 total findings • Code4rena • Aymen0909

#18

high

Delegated amounts can be forcefully removed from anyone in the TwabController

high

`Vault.mintYieldFee` FUNCTION CAN BE CALLED BY ANYONE TO MINT `Vault Shares` TO ANY RECIPIENT ADDRESS

high

`_amountOut` is representing assets and shares at the same time in the `liquidate` function

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

medium

`TwabLib::getTwabBetween` can return innacurate balances if `_startTime` and `_endTime` aren't safely bounded

medium

Lack of Slippage Protection in `withdraw`/`redeem` Functions of the Vault

Feb '24

Spectra

Spectra

80.57 USDC • 1 total finding • Code4rena • Aymen0909

#17

medium

PrincipalToken is not ERC-5095 compliant

Rio Network

Rio Network

955.40 USDC • 3 total findings • Sherlock • Aymen0909

#15

high

Withdrawals will be impossible after `queueCurrentEpochSettlement` and `settleEpochFromEigenLayer` are called

high

`queueOperatorStrategyExit` doesn't decrease the operator shares allocation

medium

`requestWithdrawal` doesn't estimate accurately the available shares for withdrawals

AI Arena

AI Arena

67.08 USDC • 5 total findings • Code4rena • Aymen0909

#74

high

Since you can reroll with a different fighterType than the NFT you own, you can reroll bypassing maxRerollsAllowed and reroll attributes based on a different fighterType

high

Player can mint more fighter NFTs during claim of rewards by leveraging reentrancy on the `claimRewards() function `

high

Fighters cannot be minted after the initial generation due to uninitialized `numElements` mapping

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)

HydraDX

HydraDX

175.73 USDC • 1 total finding • Code4rena • Aymen0909

#14

medium

[M09] No slippage check in `remove_liquidity` function in omnipool can lead to slippage losses during liquidity withdrawal.

Jan '24

Decent

Decent

23.19 USDC • 2 total findings • Code4rena • Aymen0909

#49

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

medium

Missing access control on UTB:receiveFromBridge allows UTB swaps to be executed without spending bridge fees while bypassing fee/swap instruction signature verification

Salty.IO

Salty.IO

54.81 USDC • 4 total findings • Code4rena • Aymen0909

#88

high

When borrowers repay USDS, it is sent to the wrong address, allowing anyone to burn Protocol Owned Liquidity and build bad debt for USDS

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

medium

SALT staker can get extra voting power by simply unstaking their xSALT

medium

Impossible to change managed wallets with `proposeWallets` after first rejection

Opus

Opus

1,486.04 USDC • Code4rena • Aymen0909

#10

Curves

Curves

5.8 USDC • 5 total findings • Code4rena • Aymen0909

#93

high

Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale

high

Unrestricted claiming of fees due to missing balance updates in `FeeSplitter`

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

onBalanceChange causes previously unclaimed rewards to be cleared

reNFT

reNFT

3.99 USDC • Code4rena • Aymen0909

#66

Dec '23

Revolution Protocol

Revolution Protocol

26.5 USDC • 2 total findings • Code4rena • Aymen0909

#64

medium

Since buyToken function has no slippage checking, users can get less tokens than expected when they buy tokens directly

medium

Bidder can use donations to get VerbsToken from auction that already ended.

Ethereum Credit Guild

Ethereum Credit Guild

247.49 USDC • 2 total findings • Code4rena • Aymen0909

#51

medium

There is no way to liquidate a position if it breaches maxDebtPerCollateralToken value creating bad debt.

medium

LendingTerm::debtCeiling() can return wrong debt as the min() is evaluated incorrectly

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

256.96 USDC • 4 total findings • Code4rena • Aymen0909

#16

high

The price of rsEHT could be manipulated by the first staker

high

Protocol mints less rsETH on deposit than intended

medium

Lack of slippage control on LRTDepositPool.depositAsset

medium

Update in strategy will cause wrong issuance of shares

Oct '23

NextGen

NextGen

0.15 USDC • 1 total finding • Code4rena • Aymen0909

#112

high

Attacker can reenter to mint all the collection supply

The Wildcat Protocol

The Wildcat Protocol

310.93 USDC • 3 total findings • Code4rena • Aymen0909

#29

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

high

Borrowers can escape from paying half of the penalty fees by closing the market, and those remaining penalty fees will be covered by the lender who withdraws last

high

Borrower can drain all funds of a sanctioned lender

zkSync Era

zkSync Era

929.9 USDC • Code4rena • Aymen0909

#29

Sep '23

Venus Prime

Venus Prime

4.37 USDC • Code4rena • Aymen0909

#39

Centrifuge

Centrifuge

1,275.95 USDC • 2 total findings • Code4rena • Aymen0909

#8

medium

Investors claiming their maxDeposit by using the LiquidityPool.deposit() will cause that other users won't be able to claim their maxDeposit/maxMint

medium

Cached `DOMAIN_SEPARATOR` is incorrect for tranche tokens potentially breaking permit integrations

Ondo Finance

Ondo Finance

7.08 USDC • Code4rena • Aymen0909

#32

Aug '23

Dopex

Dopex

208.46 USDC • 4 total findings • Code4rena • Aymen0909

#55

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

high

The peg stability module can be compromised by forcing lowerDepeg to revert.

high

`UniV3LiquidityAMO::recoverERC721` will cause `ERC721` tokens to be permanently locked in `rdpxV2Core`

medium

`sync` function in `RdpxV2Core.sol` should be called in multiple scenarios to account for the balance changes that occurs

PoolTogether V5: Part Deux

PoolTogether V5: Part Deux

116.52 USDC • 1 total finding • Code4rena • Aymen0909

#21

high

`rngComplete` function should only be called by `rngAuctionRelayer`

Tangible Caviar

Tangible Caviar

110.34 USDC • Code4rena • Aymen0909

#48

Jul '23

Moonwell

Moonwell

725.97 USDC • 1 total finding • Code4rena • Aymen0909

#14

medium

`fastTrackProposalExecution` should only be callable when `TemporalGovernor` is paused

Amphora Protocol

Amphora Protocol

22.71 USDC • Code4rena • Aymen0909

#22

Tokemak

Tokemak

2,156.95 USDC • 5 total findings • Sherlock • Aymen0909

#13

high

`queueNewRewards` transferring wrong amount of reward token

high

`averagePrice` has wrong decimals due to `updatePricingInfo` wrong calculation

high

Some `idle` amount is neglected in `LMPVault._withdraw` function

medium

Incorrect amount given as input to `_handleRebalanceIn` when `flashRebalance` is called

medium

Did not remove vault from `_vaultsByType` when calling in `LMPVaultRegistry.removeVault`

PoolTogether

PoolTogether

1,733.35 USDC • 6 total findings • Code4rena • Aymen0909

#14

high

Delegated amounts can be forcefully removed from anyone in the TwabController

high

`Vault.mintYieldFee` FUNCTION CAN BE CALLED BY ANYONE TO MINT `Vault Shares` TO ANY RECIPIENT ADDRESS

high

`_amountOut` is representing assets and shares at the same time in the `liquidate` function

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

medium

`TwabLib::getTwabBetween` can return innacurate balances if `_startTime` and `_endTime` aren't safely bounded

medium

Lack of Slippage Protection in `withdraw`/`redeem` Functions of the Vault

Nouns DAO

Nouns DAO

55.3 USDC • Code4rena • Aymen0909

#17

Jun '23

Stader Labs

Stader Labs

1,743.34 USDC • 4 total findings • Code4rena • Aymen0909

#17

medium

Owner in VaultProxy.sol is address(0)

medium

Chainlink's `latestRoundData` may return stale or incorrect result

medium

`updatePoolAddress` functions always reverts when updating existing poolId

medium

`pause/unpause` functionnalities not implemented in many pausable contracts

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

62.33 USDC • Code4rena • Aymen0909

#64

Iron Bank

Iron Bank

0.03 USDC • 2 total findings • Sherlock • Aymen0909

#23

medium

Chainlink's `latestRoundData()` can return stale or incorrect result

medium

Missing checks for whether Arbitrum Sequencer is active

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

78.01 USDC • 5 total findings • Sherlock • Aymen0909

#25

high

`mintRebalancer` and `burnRebalancer` functions missing `onlyBalancer` modifier

high

Wrong pool address used for `DAIEthOracle` in `StableOracleDAI` contract

high

Error in the calculation of `amountToSellUnits` in `BuyUSSDSellCollateral` function

medium

Chainlink's `latestRoundData()` can return stale or incorrect result

medium

Risk of loss of funds when calling `mintForToken`

Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

688.35 USDC • Code4rena • Aymen0909

#25

Ajna Protocol

Ajna Protocol

58.52 USDC • Code4rena • Aymen0909

#46

Apr '23

EigenLayer Contest

EigenLayer Contest

1,391.84 USDC • Code4rena • Aymen0909

#14

JOJO Exchange

JOJO Exchange

235.05 USDC • 1 total finding • Sherlock • Aymen0909

#34

medium

No slippage protection in `FlashLoanLiquidate`

ENS Contest

ENS Contest

59.79 USDC • Code4rena • Aymen0909

#20

Frankencoin

Frankencoin

43.7 USDC • 1 total finding • Code4rena • Aymen0909

#59

medium

function `restructureCapTable()` in Equity.sol not functioning as expected

Caviar Private Pools

Caviar Private Pools

8.03 USDC • 1 total finding • Code4rena • Aymen0909

#72

medium

Flash loan fee is incorrect in Private Pool contract

Rubicon v2

Rubicon v2

0.44 USDC • 1 total finding • Code4rena • Aymen0909

#122

medium

Calling `Position._marketBuy` and `Position._marketSell` functions that calculate `_fee` by dividing by `10000` can cause incorrect calculations

Mar '23

Gitcoin

Gitcoin

3.92 USDC • Sherlock • Aymen0909

#70

Asymmetry contest

Asymmetry contest

23.92 USDC • Code4rena • Aymen0909

#99

Canto Identity Subprotocols contest

Canto Identity Subprotocols contest

100.36 USDC • Code4rena • Aymen0909

#20

Y2K

Y2K

2.35 USDC • 1 total finding • Sherlock • Aymen0909

#59

high

owner rollover queue index is always changed in `enlistInRollover`

Neo Tokyo contest

Neo Tokyo contest

19.3 USDC • Code4rena • Aymen0909

#22

Wenwin contest

Wenwin contest

21.7 USDC • Code4rena • Aymen0909

#26

Feb '23

Surge

Surge

26.07 USDC • 1 total finding • Sherlock • Aymen0909

#19

medium

`feeRecipient` can be set to `address(0)` when `feeMantissa != 0`

OlympusDAO

OlympusDAO

161.92 USDC • 1 total finding • Sherlock • Aymen0909

#27

high

Error in `userRewardDebts` update in the `_claimInternalRewards`/`_claimExternalRewards` functions

Blueberry

Blueberry

14.61 USDC • 1 total finding • Sherlock • Aymen0909

#35

medium

Chainlink's `latestRoundData()` function missing check for round completeness

Jan '23

Popcorn contest

Popcorn contest

255.11 USDC • 3 total findings • Code4rena • Aymen0909

#50

high

Staking rewards can be drained

medium

Faulty Escrow config will lock up reward tokens in Staking contract

medium

Vault fees can be set to anything when initilizing

Canto Identity Protocol contest

Canto Identity Protocol contest

72.33 CANTO • Code4rena • Aymen0909

#12

Numoen contest

Numoen contest

45.43 USDC • Code4rena • Aymen0909

#20

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

38.17 USDC • 2 total findings • Code4rena • Aymen0909

#58

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts

medium

Users may not claim Erc1155 rewards when the Quest has ended

Drips Protocol contest

Drips Protocol contest

131.98 USDC • Code4rena • Aymen0909

#11

Timeswap contest

Timeswap contest

48.54 USDC • Code4rena • Aymen0909

#21

Ondo Finance contest

Ondo Finance contest

336.94 USDC • Code4rena • Aymen0909

#12

Reserve contest

Reserve contest

194.03 USDC • Code4rena • Aymen0909

#25

Astaria contest

Astaria contest

88.11 USDC • Code4rena • Aymen0909

#50

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

38.76 USDC • Code4rena • Aymen0909

#54

Dec '22

Papr contest

Papr contest

437.99 USDC • Code4rena • Aymen0909

#16

GoGoPool contest

GoGoPool contest

78.95 USDC • 2 total findings • Code4rena • Aymen0909

#61

medium

MinipoolManager: recordStakingError function does not decrease minipoolCount leading to too high GGP rewards for staker

medium

State Transition: Minipools can be created using other operator's AVAX deposit via recreateMinipool

Forgeries contest

Forgeries contest

71.66 USDC • Code4rena • Aymen0909

#19

Caviar contest

Caviar contest

14.83 USDC • Code4rena • Aymen0909

#45

Tigris Trade contest

Tigris Trade contest

1,009.9 USDC • 1 total finding • Code4rena • Aymen0909

#18

high

Not enough margin pulled or burned from user when adding to a position

prePO contest

prePO contest

53.17 USDC • Code4rena • Aymen0909

#29

Escher contest

Escher contest

0.84 USDC • 1 total finding • Code4rena • Aymen0909

#70

high

`LPDA` price can underflow the price due to bad settings and potentially brick the contract

Nov '22

ParaSpace contest

ParaSpace contest

148.85 USDC • 1 total finding • Code4rena • Aymen0909

#44

high

Anyone can prevent themselves from being liquidated as long as they hold one of the supported NFTs

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

215.01 USDC • 2 total findings • Code4rena • Aymen0909

#36

medium

GiantMevAndFeesPool.previewAccumulatedETH function: "accumulated" variable is not updated correctly in for loop leading to result that is too low

medium

Calling `updateNodeRunnerWhitelistStatus` function always reverts

Blur Exchange contest

Blur Exchange contest

64.77 USDC • Code4rena • Aymen0909

#27

LooksRare Aggregator contest

LooksRare Aggregator contest

80.83 USDC • Code4rena • Aymen0909

#22

SIZE contest

SIZE contest

65.42 USDC • Code4rena • Aymen0909

#30

Debt DAO contest

Debt DAO contest

110.58 USDC • Code4rena • Aymen0909

#43

Oct '22

zkSync v2 contest

zkSync v2 contest

229.76 USDC • Code4rena • Aymen0909

#9

Paladin - Warden Pledges contest

Paladin - Warden Pledges contest

324.23 USDC • 2 total findings • Code4rena • Aymen0909

#17

medium

Reward can be over- or undercounted in `extendPledge` and `increasePledgeRewardPerVote`

medium

Owner can transfer all ERC20 reward token out using function recoverERC20

Inverse Finance contest

Inverse Finance contest

56.12 USDC • 1 total finding • Code4rena • Aymen0909

#40

medium

Chainlink oracle data feed is not sufficiently validated and can return stale `price`

Holograph contest

Holograph contest

132.64 USDC • 1 total finding • Code4rena • Aymen0909

#28

medium

`_payoutEth()` calculates `balance` with an offset, always leaving dust `ETH` in the contract

3xcalibur contest

3xcalibur contest

383.25 USDC • Code4rena • Aymen0909

#18

Juicebox contest

Juicebox contest

887.06 USDC • 1 total finding • Code4rena • Aymen0909

#12

high

Redemption weight of tiered NFTs miscalculates, making users redeem incorrect amounts - Bug #1

Trader Joe v2 contest

Trader Joe v2 contest

0.98 USDC • 2 total findings • Code4rena • Aymen0909

#27

medium

beforeTokenTransfer called with wrong parameters in LBToken._burn

medium

Very critical `Owner` privileges can cause complete destruction of the project in a possible privateKey exploit

Blur Exchange contest

Blur Exchange contest

632.75 USDC • Code4rena • Aymen0909

#13

Sep '22

QuickSwap and StellaSwap contest

QuickSwap and StellaSwap contest

92.36 USDC • Code4rena • Aymen0909

#27

Frax Ether Liquid Staking contest

Frax Ether Liquid Staking contest

62.93 USDC • 1 total finding • Code4rena • Aymen0909

#40

medium

Centralization risk: admin have privileges: admin can set address to mint any amount of frxETH, can set any address as validator, and change important state in frxETHMinter and withdraw fund from frcETHMinter

VTVL contest

VTVL contest

63.74 USDC • Code4rena • Aymen0909

#41

Art Gobblers contest

Art Gobblers contest

55.2 USDC • Code4rena • Aymen0909

#21

Y2k Finance contest

Y2k Finance contest

52.8 USDC • Code4rena • Aymen0909

#50

PartyDAO contest

PartyDAO contest

117.97 USDC • Code4rena • Aymen0909

#40

FEI and TRIBE Redemption contest

FEI and TRIBE Redemption contest

33.6 USDC • Code4rena • Aymen0909

#13

Nouns Builder contest

Nouns Builder contest

327.51 USDC • Code4rena • Aymen0909

#47

Aug '22

Olympus DAO contest

Olympus DAO contest

629.13 USDC • 1 total finding • Code4rena • Aymen0909

#28

medium

The governance system can be held hostage by a malicious user

Nouns DAO contest

Nouns DAO contest

1,099.27 USDC • 1 total finding • Code4rena • Aymen0909

#11

medium

Loss of Veto Power can Lead to 51% Attack

FIAT DAO veFDT contest

FIAT DAO veFDT contest

125.97 USDC • 1 total finding • Code4rena • Aymen0909

#30

medium

ERROR IN UPDATING **_checkpoint** IN THE **increaseUnlockTime** FUNCTION

Fraxlend (Frax Finance) contest

Fraxlend (Frax Finance) contest

67.72 USDC • Code4rena • Aymen0909

#41

Foundation Drop contest

Foundation Drop contest

62 USDC • Code4rena • Aymen0909

#47

Mimo August 2022 contest

Mimo August 2022 contest

39.03 USDC • Code4rena • Aymen0909

#44

Rigor Protocol contest

Rigor Protocol contest

62.38 USDC • Code4rena • Aymen0909

#62

Jul '22

Axelar Network v2 contest

Axelar Network v2 contest

96.59 USDC • Code4rena • Aymen0909

#21

Golom contest

Golom contest

94.66 USDC • Code4rena • Aymen0909

#75

Yield Witch v2 contest

Yield Witch v2 contest

16.94 USDC • Code4rena • Aymen0909

#53

Swivel v3 contest

Swivel v3 contest

25.71 USDC • Code4rena • Aymen0909

#65

ENS contest

ENS contest

39.87 USDC • Code4rena • Aymen0909

#69

Fractional v2 contest

Fractional v2 contest

61.94 USDC • Code4rena • Aymen0909

#88

Juicebox V2 contest

Juicebox V2 contest

38.24 USDC • Code4rena • Aymen0909

#61

Jun '22

Putty contest

Putty contest

21.24 USDC • Code4rena • Aymen0909

#84