https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

BPZ

Security Researcher

Contact Me

High

11

Total

Medium

11

Total

$6.27K

Total Earnings

#728 All Time

13x

Payouts

regular

3x

Top 25

regular

10x

Top 50

All

Sherlock

Code4rena

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

475.68 USDC • Code4rena • BPZ

#40

Jul '23

Tokemak

Tokemak

114.57 USDC • 2 total findings • Sherlock • BPZ

#40

high

The queueNewRewards function does not correctly allocate funds

medium

Users will experience a DOS when trying to deposit to a LMPVault that has its supplyLimit and walletLimit set to type(uint256).max values

Tapioca DAO

Tapioca DAO

1,066.65 USDC • 3 total findings • Code4rena • BPZ

#45

high

TOFT and USDO Modules Can Be Selfdestructed

medium

Users can borrow funds without any allowance

medium

all deposit and withdraw function in Convex and Curve nativeLP Strategy, apply slippage on internal pricing; which call real-time on chain price from Curve directly and subject to MEV

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

2,572.45 USDC • 7 total findings • Code4rena • BPZ

#23

high

`UlyssesToken` asset ID accounting error

high

Multiple issues with decimal scaling will cause incorrect accounting of hTokens and underlying tokens

high

setWeight() Logic error

high

Cross-chain messaging via Anycall will fail

medium

Lack of slippage protection can lead to significant loss of user funds

medium

## vMaia is an ERC-4626 compliant but maxWithdraw & maxRedeem functions are not fully up to EIP-4626's specification

medium

UlyssesPool.sol does not match EIP4626 because of preview functions

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

883.33 USDC • Code4rena • BPZ

#27

Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

258.7 USDC • 2 total findings • Code4rena • BPZ

#32

high

Incorrect `blocksPerYear` constant in `WhitepaperInterestRateModel`

medium

ShortFall contract might transfer incorrect amount of tokens to the highest bidder.

Ajna Protocol

Ajna Protocol

309.08 USDC • 1 total finding • Code4rena • BPZ

#28

high

User can exponentially increase the value of their position through the memorializePositions function

Apr '23

Frankencoin

Frankencoin

0.07 USDC • 1 total finding • Code4rena • BPZ

#69

medium

function `restructureCapTable()` in Equity.sol not functioning as expected

Mar '23

Asymmetry contest

Asymmetry contest

98.95 USDC • 3 total findings • Code4rena • BPZ

#51

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

medium

No slippage protection on `stake()` in SafEth.sol

medium

Lack of deadline for uniswap AMM

Y2K

Y2K

97.68 USDC • 1 total finding • Sherlock • BPZ

#53

high

The mintRollovers function will skip users

Neo Tokyo contest

Neo Tokyo contest

184.41 USDC • 1 total finding • Code4rena • BPZ

#15

high

Underflow of `lpPosition.points` during withdrawLP causes huge reward minting

Jan '23

Ondo Finance contest

Ondo Finance contest

36.24 USDC • Code4rena • BPZ

#19

Dec '22

Caviar contest

Caviar contest

173.84 USDC • 1 total finding • Code4rena • BPZ

#31

medium

Pair price may be manipulated by direct transfers