Security Researcher
High
Total
Medium
Total Earnings
#1025 All Time
Payouts
Top 25
Top 50
All
Sherlock
Code4rena
Oct '23
0.47 USDC • 2 total findings • Code4rena • Delvir0
#111
high
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
medium
Auction winner can prevent payments via `safeTransferFrom` callback
Sep '23
771.3 USDC • 1 total finding • Code4rena • Delvir0
#14
Admin can't burn tokens from blocklisted addresses because of a check in _beforeTokenTransfer
Aug '23
26.24 USDC • 2 total findings • Sherlock • Delvir0
#16
repayLoan can be DOSSed
Anyone can roll a loan
Jul '23
0.20 USDC • Sherlock • Delvir0
#43
128.41 USDC • 1 total finding • Sherlock • Delvir0
Not setting an init value of lastEpochClaimed[msg.sender] could lead to OOG
64.98 USDC • 1 total finding • Sherlock • Delvir0
#11
Incorrect function flow when using DirectBuyIssuer to fill order.
Jun '23
625.13 USDC • 2 total findings • Sherlock • Delvir0
User won't receive vusd when withdrawing if balance vusd of InsuranceFund == 0
Transferring supported pool tokens while totalsupply == 0 will break `despositFor` for the next user
May '23
0.03 USDC • 2 total findings • Sherlock • Delvir0
#23
Missing stale price check from Chainlink oracle
Missing sequencer check for ARB network in `PriceOracle.sol`
0.00 USDC • 4 total findings • Sherlock • Delvir0
#94
_mint and _burn are open to the public
`UniV3SwapInput` doesn't implement a deadline
ethOracle address set to 0
Chainlink returned price not checked
Apr '23
0.02 USDC • 1 total finding • Sherlock • Delvir0
#54
Fee on transfer tokens will break withdrawal of collateral
29.78 USDC • 2 total findings • Code4rena • Delvir0
#89
Reward accounting is incorrect in BathBuddy contract
Some offers can't be cancelled
Mar '23
41.79 USDC • 1 total finding • Sherlock • Delvir0
#57
Insufficient Chainlink feed validation
Feb '23
6.94 USDC • 1 total finding • Sherlock • Delvir0
#21
Frontrun attack possible with Pool.approve
100.59 USDC • 1 total finding • Sherlock • Delvir0
#30
Due to incorrect way of tracking rewards by LP's an attacker can receive an unfair share of yield accumulated in MainVault.sol
Jan '23
51.32 USDC • Code4rena • Delvir0
#52