https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/78934965-8672-48f3-89eb-aa87c2660b3f.jpg

BAHOZ

Security Researcher

bounty hunter | warden @code4rena | dm for private audits

Contact Me

High

6

Total

Medium

10

Total

$5.83K

Total Earnings

#707 All Time

9x

Payouts

regular

3x

Top 10

regular

5x

Top 25

regular

8x

Top 50

All

Sherlock

Code4rena

CodeHawks

Feb '24

UniStaker Infrastructure

UniStaker Infrastructure

694.3 USDC • Code4rena • BAHOZ

#5

Jul '23

Foundry DeFi Stablecoin CodeHawks Audit Contest

Foundry DeFi Stablecoin CodeHawks Audit Contest

16.33 USDC • 4 total findings • CodeHawks • BAHOZ

#70

medium

All of the USD pair price feeds doesn't have 8 decimals

medium

Anyone can burn **DecentralizedStableCoin** tokens with `burnFrom` function

gas

Double checks

gas

Use `==` instead for `<=` for `uints` when comparing for `zero` values

CodeHawks Escrow Contract - Competition Details

CodeHawks Escrow Contract - Competition Details

70.04 USDC • 3 total findings • CodeHawks • BAHOZ

#41

medium

[H-01] Lack of emergency withdraw function when no arbiter is set

low

[L] If the arbiter is not set, arbiter fee should not be positive

gas

Reentrancy guard and nonReentrant modifier not required.

May '23

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

3,805.62 USDC • Code4rena • BAHOZ

#14

DODO Margin Trading

DODO Margin Trading

105.99 USDC • 1 total finding • Sherlock • BAHOZ

#5

high

Attacker can drain all funds in the wallet using a flashloan

Footium

Footium

641.27 USDC • 4 total findings • Sherlock • BAHOZ

#4

high

Sale of Club NFT may be frontrunned

medium

Users can be blocked from minting players from previous seasons

medium

FootiumClub's safeMint() uses unsafe _mint()

medium

Return of arbitrary ERC20 transfer is not checked in escrow

Apr '23

Teller

Teller

126.24 USDC • 5 total findings • Sherlock • BAHOZ

#34

high

Borrower can omit paying collateral and steal principle

high

Liquidators can steal collateral by force liquidating the borrower

medium

Fee on transfer/rebasing tokens may stuck in the escrow contract

medium

Market Owner and Protocol Owner can steal principles by frontrunning accepted bids

medium

Market Owners can steal collaterals by backrunning created bids

Dec '22

Forgeries contest

Forgeries contest

320.13 USDC • 1 total finding • Code4rena • BAHOZ

#14

medium

VRFNFTRandomDraw admin can prevent created or started raffle from taking place

Caviar contest

Caviar contest

47.25 USDC • 2 total findings • Code4rena • BAHOZ

#42

high

Liquidity providers may lose funds when adding liquidity

high

First depositor can break minting of shares