https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

Co0nan

Security Researcher

Contact Me

High

4

Total

Medium

10

Total

$4.93K

Total Earnings

#796 All Time

9x

Payouts

regular

1x

Top 10

regular

4x

Top 25

regular

8x

Top 50

All

Code4rena

Jul '23

PoolTogether

PoolTogether

165.56 USDC • 2 total findings • Code4rena • Co0nan

#48

high

Delegated amounts can be forcefully removed from anyone in the TwabController

high

`Vault.mintYieldFee` FUNCTION CAN BE CALLED BY ANYONE TO MINT `Vault Shares` TO ANY RECIPIENT ADDRESS

Jun '23

Lybra Finance

Lybra Finance

327.03 USDC • 4 total findings • Code4rena • Co0nan

#28

high

EUSD.mint function wrong assumption of cases when calculated sharesAmount = 0

medium

Incorrect function call in LybraRETHVault's getAssetPrice

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called

medium

`stakerewardV2pool.withdraw()` should check the user's boost lock status.

Llama

Llama

54.53 USDC • 1 total finding • Code4rena • Co0nan

#21

medium

It is not possible to execute actions that require ETH (or other protocol token)

Stader Labs

Stader Labs

2,772.43 USDC • 1 total finding • Code4rena • Co0nan

#8

medium

Protocol will not benefit from slashing mechanism when remaining penalty bigger than minThreshold

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

23.91 USDC • 1 total finding • Code4rena • Co0nan

#66

medium

RestakeToken function is not permissionless

Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

840.31 USDC • 2 total findings • Code4rena • Co0nan

#17

medium

Borrow rate calculation can cause VToken.accrueInterest() to revert, DoSing all major functionality

medium

Exchange Rate can be manipulated

Apr '23

EigenLayer Contest

EigenLayer Contest

528.25 USDC • Code4rena • Co0nan

#20

Mar '23

Asymmetry contest

Asymmetry contest

162.61 USDC • 3 total findings • Code4rena • Co0nan

#40

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

medium

Stuck ether when use function `stake` with empty `derivatives`(`derivativeCount` = 0)

medium

In de-peg scenario, forcing full exit from every derivative & immediately re-entering can cause big losses for depositors

Feb '23

Ethos Reserve contest

Ethos Reserve contest

61.26 USDC • Code4rena • Co0nan

#33