https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/1e91a952-626b-4fcc-bba0-d46fa2ff6ba5.jpg

Deivitto

Security Researcher

Engineering & coffee āš™ļøā˜• Blockchain Security Researcher & bug hunter šŸ•µļøšŸ”Ž @SpearbitDAO | @code4rena @AuditorToolbox šŸ–Šļø Request an audit https://t.co/IJYStSwSHF

Contact Me

High

5

Total

Medium

23

Total

$13.13K

Total Earnings

#478 All Time

59x

Payouts

regular

6x

Top 10

regular

27x

Top 25

regular

46x

Top 50

All

Sherlock

Code4rena

CodeHawks

Jul '24

MakerDAO Endgame

MakerDAO Endgame

970.22 USDC • Sherlock • Deivitto

#58

May '24

Munchables

Munchables

0 USDC • Code4rena • Deivitto

#17

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

26.62 USDC • 4 total findings • CodeHawks • Deivitto

#102

high

Sandwich attack to steal all ERC-20 tokens in the Fees contract

high

Hardcoded Router Address May Cause Token Lockup in Non-Standard Networks

medium

Single-step process for critical ownership transfer is risky

gas

Don't use draft versions in production

Feb '23

Surge

Surge

118.11 USDC • 1 total finding • Sherlock • Deivitto

#17

medium

`fee`s accrued can be zero on some parameters even if `fee`s are expected to exist

Ethos Reserve contest

Ethos Reserve contest

370.05 USDC • Code4rena • Deivitto

#27

Jan '23

Popcorn contest

Popcorn contest

562.23 USDC • 2 total findings • Code4rena • Deivitto

#36

medium

Fee on transfer token not supported

medium

[NAZ-M2] Unchecked return of `execute()`

Numoen contest

Numoen contest

578.85 USDC • 1 total finding • Code4rena • Deivitto

#14

medium

Fee on transfer tokens will not behave as expected

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

13.92 USDC • 1 total finding • Code4rena • Deivitto

#75

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts

Drips Protocol contest

Drips Protocol contest

131.98 USDC • Code4rena • Deivitto

#11

Cooler

Cooler

55.05 USDC • 2 total findings • Sherlock • Deivitto

#26

high

ERC20 not checked on transfer

medium

`loan.amount` can be repaid without altering `loan.collateral`

Astaria contest

Astaria contest

51.32 USDC • Code4rena • Deivitto

#52

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

44.83 USDC • 1 total finding • Code4rena • Deivitto

#53

medium

SmartAccount.sol is intended to be upgradable but inherits from contracts that contain storage and no gaps

Notional Update

Notional Update

144.57 USDC • 1 total finding • Sherlock • Deivitto

#5

medium

`_getOraclePairPrice` doesn't allow some expected tokens to be used

Dec '22

GoGoPool contest

GoGoPool contest

68.09 USDC • 1 total finding • Code4rena • Deivitto

#64

medium

Bypass `whenNotPaused` modifier

Forgeries contest

Forgeries contest

45.71 USDC • Code4rena • Deivitto

#21

Tigris Trade contest

Tigris Trade contest

220.11 USDC • 2 total findings • Code4rena • Deivitto

#39

medium

Must approve 0 first

medium

`_handleDeposit` and `_handleWithdraw` do not account for tokens with decimals higher than 18

Maverick contest

Maverick contest

119.07 USDC • Code4rena • Deivitto

#12

Nov '22

ParaSpace contest

ParaSpace contest

1,028.49 USDC • Code4rena • Deivitto

#24

Canto contest

Canto contest

73.58 CANTO • Code4rena • Deivitto

#10

Opyn Crab Netting

Opyn Crab Netting

390.09 USDC • 1 total finding • Sherlock • Deivitto

#12

medium

Malicious owner can lock funds

Isomorph

Isomorph

282.34 USDC • 1 total finding • Sherlock • Deivitto

#16

medium

Use of a hardcoded assumption of 1 USDC = 1 USD can lead into all protocol to fail and loss of value

Redacted Cartel contest

Redacted Cartel contest

93.14 USDC • Code4rena • Deivitto

#40

Telcoin

Telcoin

30.30 USDC • 1 total finding • Sherlock • Deivitto

#6

medium

ERC20 transfer / transferFrom with not checked return value

Buffer Finance

Buffer Finance

71.36 USDC • 2 total findings • Sherlock • Deivitto

#9

medium

Withdraw can reverts and locks funds

medium

ERC20 `approve` can fail for some tokens

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

543.7 USDC • Code4rena • Deivitto

#26

Blur Exchange contest

Blur Exchange contest

22.22 USDC • Code4rena • Deivitto

#30

LooksRare Aggregator contest

LooksRare Aggregator contest

36.34 USDC • Code4rena • Deivitto

#24

SIZE contest

SIZE contest

65.42 USDC • Code4rena • Deivitto

#30

Debt DAO contest

Debt DAO contest

672.02 USDC • 1 total finding • Code4rena • Deivitto

#28

medium

address.call{value:x}() should be used instead of payable.transfer()

Chainlink Staking contest

Chainlink Staking contest

139.59 USDC • Code4rena • Deivitto

#17

Oct '22

Inverse Finance contest

Inverse Finance contest

55.74 USDC • Code4rena • Deivitto

#41

Holograph contest

Holograph contest

577.36 USDC • 1 total finding • Code4rena • Deivitto

#17

medium

Bad source of randomness

The Graph L2 bridge contest

The Graph L2 bridge contest

20.79 USDC • Code4rena • Deivitto

#16

Blur Exchange contest

Blur Exchange contest

50.48 USDC • Code4rena • Deivitto

#22

Sep '22

QuickSwap and StellaSwap contest

QuickSwap and StellaSwap contest

150.82 USDC • Code4rena • Deivitto

#21

Frax Ether Liquid Staking contest

Frax Ether Liquid Staking contest

43.64 USDC • Code4rena • Deivitto

#53

VTVL contest

VTVL contest

35.17 USDC • Code4rena • Deivitto

#55

Art Gobblers contest

Art Gobblers contest

930.57 USDC • Code4rena • Deivitto

#14

Y2k Finance contest

Y2k Finance contest

245.01 USDC • 1 total finding • Code4rena • Deivitto

#28

medium

Fee-on-Transfer tokens cause problems in multiple places

PartyDAO contest

PartyDAO contest

161.8 USDC • Code4rena • Deivitto

#26

FEI and TRIBE Redemption contest

FEI and TRIBE Redemption contest

33.58 USDC • Code4rena • Deivitto

#14

Canto Dex Oracle contest

Canto Dex Oracle contest

146.62 CANTO • 1 total finding • Code4rena • Deivitto

#10

medium

Calculated `token0TVL` may be zero under certain scenarios

Nouns Builder contest

Nouns Builder contest

402.55 USDC • Code4rena • Deivitto

#43

Aug '22

Olympus DAO contest

Olympus DAO contest

127.02 USDC • Code4rena • Deivitto

#51

Nouns DAO contest

Nouns DAO contest

1,197.57 USDC • 1 total finding • Code4rena • Deivitto

#8

medium

Loss of Veto Power can Lead to 51% Attack

FIAT DAO veFDT contest

FIAT DAO veFDT contest

112.04 USDC • Code4rena • Deivitto

#31

Fraxlend (Frax Finance) contest

Fraxlend (Frax Finance) contest

183.97 USDC • Code4rena • Deivitto

#24

Foundation Drop contest

Foundation Drop contest

117.48 USDC • 1 total finding • Code4rena • Deivitto

#19

medium

NFT of NFT collection or NFT drop collection can be locked when calling _mint or mintCountTo function to mint it to a contract that does not support ERC721 protocol

Mimo August 2022 contest

Mimo August 2022 contest

127.44 USDC • Code4rena • Deivitto

#27

Rigor Protocol contest

Rigor Protocol contest

388.06 USDC • 1 total finding • Code4rena • Deivitto

#23

high

Builder can halve the interest paid to a community owner due to arithmetic rounding

Jul '22

Axelar Network v2 contest

Axelar Network v2 contest

117.04 USDC • Code4rena • Deivitto

#17

Golom contest

Golom contest

262.24 USDC • Code4rena • Deivitto

#45

Yield Witch v2 contest

Yield Witch v2 contest

56.11 USDC • Code4rena • Deivitto

#27

ENS contest

ENS contest

222.29 USDC • Code4rena • Deivitto

#28

Fractional v2 contest

Fractional v2 contest

103.94 USDC • Code4rena • Deivitto

#65

Jun '22

Notional x Index Coop

Notional x Index Coop

144.37 USDC • Code4rena • Deivitto

#26

May '22

veToken Finance contest

veToken Finance contest

100.03 USDT • Code4rena • Deivitto

#52

Velodrome Finance contest

Velodrome Finance contest

49.95 USDC • Code4rena • Deivitto

#57

Rubicon contest

Rubicon contest

0.1 USDC • 1 total finding • Code4rena • Deivitto

#87

medium

Use `safeTransfer()`/`safeTransferFrom()` instead of `transfer()`/`transferFrom()`