Security Researcher
High
Total
Medium
Total Earnings
#532 All Time
Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
CodeHawks
Feb '25
0.04 USDC • 1 total finding • Sherlock • DenTonylifer
medium
Allocation per user is incorrectly calculated in "updateParticipation()"
Jan '25
1.11 USDC • 2 total findings • Sherlock • DenTonylifer
#94
Users can force auctions to fail by redeeming large amounts right before auction ends
Blocklisted bidder can force auction to fail
90.69 USDC • Sherlock • DenTonylifer
#84
Dec '24
47.33 op • 1 total finding • CodeHawks • dentonylifer
#61
low
Incorrect event emitted in `setUpdateWeightRunnerAddress()` function
2.02 OP • 3 total findings • Sherlock • DenTonylifer
#47
high
User can withdraw part of order funds after order was executed
Pseudo-random `orderId` allows to drain protocol
Malicious order executor can completely dran protocol
19.41 OP • 4 total findings • Sherlock • DenTonylifer
#46
ETH will be sent to wrong address during liquidation
Lack of access control in `executeSetterFunction()`
Excess ETH sent during liquidation will be stuck forever
User's funds are not transfered during liquidation
Nov '24
74.96 USDC • 3 total findings • Sherlock • DenTonylifer
#23
Wrong calculation of entry fees leads to overpayment of fees
Wrong calculation of marketFunds leads to losses for other markets.
Lack of slippage protection fot ETH spend/received in ReputationMarket.sol
85.96 USDC • 3 total findings • Sherlock • DenTonylifer
#32
NFT will be locked in buyOrder
Incentives will not be updated in updateFunds() function
Previous owner can steal unclaimed bribes from new owner of veNFTVault
Sep '24
9.11 USDC • 1 total finding • Sherlock • DenTonylifer
Protocol does not work with fee-on-transfer tokens
Aug '24
10.48 USDC • 1 total finding • Sherlock • DenTonylifer
#44
Repayment will revert due to wrong balance mismatch check
Jul '24
237.63 USDC • Sherlock • DenTonylifer
#87
Jun '24
827.34 USDC • 1 total finding • Sherlock • DenTonylifer
#6
Anyone can break accounting of rewards from Convex
May '24
5,375 USDC • 1 total finding • Sherlock • DenTonylifer
StrategyPassiveManagerVelodrome does not take into account unharvested fees
Apr '24
24.58 USDC + NOYA stars • 2 total findings • Code4rena • d_tony7470
#75
`Keepers` does not implement EIP712 correctly on multiple occasions
`maxDeposit`, `maxMint`, `maxWithdraw`, and `maxRedeem` functions do not return 0 when they should
4.74 USDC • 1 total finding • Sherlock • DenTonylifer
#35
Anyone can steal pool shares from lender group if no-revert-on-failure tokens are used
7.37 USDC • 2 total findings • Code4rena • d_tony7470
#100
Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral
Attacker can frontrun to prevent vaults from being removed from the dNFT owner's position
Mar '24
1.18 USDC • 1 total finding • Sherlock • DenTonylifer
Highest bidder can cancel his bid
Feb '24
1,370.03 USDC • 1 total finding • Sherlock • DenTonylifer
#4
Missing zero amount check may lead to loss of funds
Jan '24
1,903.49 USDC • 1 total finding • CodeHawks • dentonylifer
All claimed rewards will be lost for the users using the account abstraction wallet
2.64 USDC • 1 total finding • Sherlock • DenTonylifer
#9
Incorrect removal of a council member
Dec '23
0.15 USDC • 1 total finding • CodeHawks • dentonylifer
#97
Missing deadline check allow pending transactions to be maliciously executed