Security Researcher
Smart Contract Security Researcher
High
Total
Medium
Total Earnings
#1585 All Time
Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Cantina
CodeHawks
Sep '25
0.02 OP • 2 total findings • Sherlock • Chonkov
#50
high
Malicious user could intentionally deprive users of the protocol from receiving rewards by staking "dust amounts"
medium
When the contracts are initially deployed, excess amount of rewards could be minted
Apr '25
11.86 USDC • 1 total finding • Cantina • chonkov
#73
Mar '25
14.85 USDC • 1 total finding • Cantina • chonkov
#31
Feb '25
0.00 usdc • 1 total finding • CodeHawks • chonkov
#396
Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations
Dec '24
0.03 USDC • 2 total findings • Code4rena • Gosho
#66
Users can claim more that their actual allotment
Incorrect referral fee calculations
0 USDC • 1 total finding • Code4rena • Gosho
#36
Minting zero tokens when underlyingToken is not Ether in cashIn()
Nov '24
94.59 USDC • 1 total finding • Sherlock • Chonkov
Front-running of `claim(...)` can lead to stealing rewards from investors
Oct '24
131.06 OP • 1 total finding • Sherlock • Chonkov
Users can't claim multiple times when a distribution happens over multiple epochs
11.29 USDC • 2 total findings • Cantina • chonkov
#85
Aug '24
115.5 USDC • 3 total findings • Code4rena • Gosho
#17
`PhiFactory:claim` Potentially Causing Loss of Funds If `mintFee` Changed Beforehand
Contract `PhiNFT1155` can't be paused
Attacker can DOS user from selling shares of a credId
Jul '24
0.39 USDC • 1 total finding • Code4rena • Gosho
#48
Single plot can be occupied by multiple renters
Jun '24
151.72 USDC • 2 total findings • Code4rena • Gosho
Due to the use of `msg.value` in for loop, anyone can drain all the funds from the `THORChain_Router` contract
[M-02] Incorrect call argument in `THORChain_Router::_transferOutAndCallV5`, leading to grief/steal of `THORChain_Aggregator`'s funds or DoS