https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/3c3523c2-9172-4502-8be6-cac8c98d3685.jpg

CRYP70

Security Researcher

Software Engineer and Red Team Ops in a previous life. Security Researcher @zokyo_io

Contact Me

High

8

Total

Medium

1

Solo

13

Total

$4.58K

Total Earnings

#761 All Time

23x

Payouts

silver

1x

2nd Places

regular

4x

Top 10

regular

9x

Top 25

All

Sherlock

Code4rena

Mar '24

Revert Lend

Revert Lend

330.24 USDC • 1 total finding • Code4rena • CRYP70

#35

medium

Lack of safety buffer in `_checkLoanIsHealthy` could subject users who take out the max loan into a forced liquidation

Nov '23

Panoptic

Panoptic

11.32 USDC • Code4rena • CRYP70

#28

May '23

DODO Margin Trading

DODO Margin Trading

116.10 USDC • 1 total finding • Sherlock • CRYP70

silver

high

Missing initiator check could lead to griefing attacks

Apr '23

Rubicon v2

Rubicon v2

15.76 USDC • 2 total findings • Code4rena • CRYP70

#98

high

DOS of market operations with malicious offers

high

Some offers can't be cancelled

Mar '23

Asymmetry contest

Asymmetry contest

13.13 USDC • Code4rena • CRYP70

#110

Polynomial Protocol contest

Polynomial Protocol contest

105.15 USDC • Code4rena • CRYP70

#28

Feb '23

Surge

Surge

3.65 USDC • 1 total finding • Sherlock • CRYP70

#22

high

First depositor can steal funds from users by forcibly depositing to the lending pool

OlympusDAO

OlympusDAO

295.65 USDC • 2 total findings • Sherlock • CRYP70

#19

high

Users can steal additional rewards after withdrawing with the `claimed_` flag set as `true`

medium

User rewards will be lost when a reward token is removed from the protocol

Jan '23

Popcorn contest

Popcorn contest

202.03 USDC • 2 total findings • Code4rena • CRYP70

#54

high

First vault depositor can steal other's assets

medium

Accrued perfomance fee calculation takes wrong assumptions for share decimals, leading to loss of shares or hyperinflation

Ajna

Ajna

1,174.88 USDC • 2 total findings • Sherlock • CRYP70

#8

medium

Auction timers following liquidity can fall through the floor price causing pool insolvency

medium

Flash loans dont check deposit before and after which may result in the drainage of a pool

UXD Protocol

UXD Protocol

59.58 USDC • 1 total finding • Sherlock • CRYP70

#25

medium

Tokens Will Never Be Swapped When Calling `rebalance()` in `PerpDepository`

Dec '22

Caviar contest

Caviar contest

270.53 USDC • 3 total findings • Code4rena • CRYP70

#24

high

Liquidity providers may lose funds when adding liquidity

medium

Price will not always be 18 decimals, as expected and outlined in the comments

medium

Rounding error in buyQuote might result in free tokens

Escher contest

Escher contest

132.36 USDC • 2 total findings • Code4rena • CRYP70

#27

medium

NFTs mintable after Auction deadline expires

medium

Use of `payable.transfer()` Might Render ETH Impossible to Withdraw

Nov '22

Opyn Crab Netting

Opyn Crab Netting

577.92 USDC • 1 total finding • Sherlock • CRYP70

#10

medium

`usdcAmount` Will be Incorrect in `withdrawAuction()` When Attempting to Transfer Proportionate Amount

Oct '22

Mycelium

Mycelium

109.26 USDC • 1 total finding • Sherlock • CRYP70

#8

medium

Forcibly sending tokens to the vault can block future investors from receiving myLink causing a Denial of Service condition and loss of funds.

Sep '22

PartyDAO contest

PartyDAO contest

121.98 USDC • Code4rena • CRYP70

#33

Nouns Builder contest

Nouns Builder contest

60.77 USDC • Code4rena • CRYP70

#97

Aug '22

Sentiment

Sentiment

533.47 USDC • 1 total finding • Sherlock • CRYP70

#17

high

ERC20 Tokens with Different Decimals to 1e18 lead to Inaccurate Price Feed

Olympus DAO contest

Olympus DAO contest

54.31 USDC • Code4rena • CRYP70

#85

FIAT DAO veFDT contest

FIAT DAO veFDT contest

14.95 USDC • Code4rena • CRYP70

#72

Jul '22

Golom contest

Golom contest

149.77 USDC • Code4rena • CRYP70

#67

Swivel v3 contest

Swivel v3 contest

25.71 USDC • Code4rena • CRYP70

#65

ENS contest

ENS contest

205.89 USDC • 1 total finding • Code4rena • CRYP70

#30

medium

The `unwrapETH2LD` use `transferFrom` instead of `safeTransferFrom` to transfer ERC721 token