https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/e04c9203-1315-4314-bc56-8ee76dd2be05.jpg

CaeraDenoir

Security Researcher

Blockchain Security Researcher

Contact Me

High

6

Total

Medium

8

Total

$1.19K

Total Earnings

#1257 All Time

7x

Payouts

regular

1x

Top 25

regular

4x

Top 50

All

Code4rena

Apr '24

DYAD

DYAD

7.35 USDC • 1 total finding • Code4rena • CaeraDenoir

#101

medium

Attacker can frontrun to prevent vaults from being removed from the dNFT owner's position

Mar '24

Revert Lend

Revert Lend

418.69 USDC • 3 total findings • Code4rena • CaeraDenoir

#30

high

V3Utils.execute() does not have caller validation, leading to stolen NFT positions from users

high

Owner of a position can prevent liquidation due to the 'onERC721Received' callback

medium

Repayments and liquidations can be forced to revert by an attacker that repays miniscule amount of shares

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

267.84 USDC • 2 total findings • Code4rena • CaeraDenoir

#12

medium

Withdrawal from NFTs can be temporarily blocked

medium

Distribution can be bricked, and double claims by a few holders are possible when owner calls `LiquidInfrastructureERC20::setDistributableERC20s`

Jan '24

Salty.IO

Salty.IO

0.78 USDC • 1 total finding • Code4rena • CaeraDenoir

#117

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

Dec '23

Ethereum Credit Guild

Ethereum Credit Guild

256.04 USDC • 2 total findings • Code4rena • CaeraDenoir

#47

medium

PnL system can be broken by large users intentionally or unintentionally.

medium

Malicious borrower can decrease Guild holders reward

Oct '23

NextGen

NextGen

98.5 USDC • 3 total findings • Code4rena • CaeraDenoir

#59

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders

medium

Vulnerability in burnToMint function allowing double use of NFT

The Wildcat Protocol

The Wildcat Protocol

137.73 USDC • 2 total findings • Code4rena • CaeraDenoir

#43

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

medium

`setAnnualInterestBips()` can be abused to keep a market's reserve ratio at 90%