https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

Galturok

Security Researcher

Contact Me

High

20

Total

Medium

19

Total

$3.54K

Total Earnings

#852 All Time

21x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

5x

Top 10

All

Sherlock

Code4rena

CodeHawks

Dec '24

QuantAMM

QuantAMM

0.82 op • 1 total finding • CodeHawks • galturok

#78

medium

quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.

Alchemix Transmuter

Alchemix Transmuter

281.09 op • 3 total findings • CodeHawks • galturok

#15

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

medium

Inflated `totalAssets` in `StrategyMainnet`, `StrategyArb`, and `StrategyOp` Contracts

low

Old router retains token allowance after update

SecondSwap

SecondSwap

57.64 USDC • 4 total findings • Code4rena • TheFabled

#40

high

Users can claim more that their actual allotment

medium

Incorrect referral fee calculations

medium

Underflow in `claimable` DOSing `claim` Function

medium

Listing potential can not be purchased with discounted price

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

29.87 OP • 4 total findings • Sherlock • Galturok

#39

high

Replay Attacks Due to Improper Nonce Management in Signature Verification

high

Potential Underflow in `withdrawInterest`

medium

Unrestricted Access to `executeSetterFunction` Allows Unauthorized Approval Reset

medium

Potential for Insufficient Ether Balance During Liquidation Process

Lambo.win

Lambo.win

21.83 USDC • 1 total finding • Code4rena • TheFabled

#33

high

LamboFactory can be permanently DoS-ed due to createPair call reversal

Nov '24

vVv Launchpad - Investments & Token distribution

vVv Launchpad - Investments & Token distribution

94.59 USDC • 1 total finding • Sherlock • Galturok

gold

high

Token Claim Hijacking Due to Missing Validation

Project

Project

606.17 USDC • 1 total finding • CodeHawks • galturok

#7

high

MembershipERC1155 proxy cannot be upgraded

Oct '24

Dria

Dria

47.73 USDC • 4 total findings • CodeHawks • galturok

#28

high

Subtraction in `variance()` will revert due to underflow

high

Potential underflow vulnerability in score range calculation of `LLMOracleCoordinator::finalizeValidation`, leading to DoS.

medium

Request responses and validations can be mocked leading to extraction of fees and/or forcing other generators to lose their fees by making them outliers

medium

Users can list assets with price < 1 ERC20 (ETH, WETH), leading to potential DoS vulnerability.

Gamma Brevis Rewarder

Gamma Brevis Rewarder

131.06 OP • 1 total finding • Sherlock • Galturok

bronze

high

Inadequate Reward Claim Tracking: Prevents Full Reward Access Across Epochs

Sep '24

Liquid Staking

Liquid Staking

959.94 USDC • 2 total findings • CodeHawks • galturok

#12

medium

Griefer can permanently DOS all the deposits to the `StakingPool`

low

Handling of Empty Data Arrays in StakingPool Causes Array Out-of-Bounds Access

Boost Core Incentive Protocol

Boost Core Incentive Protocol

86.00 USDC • 3 total findings • Sherlock • Galturok

#16

high

ERC20Incentive onlyOwner Restriction Causes Operational Lock

medium

Lack of Validation in Referral Fee Enables Full Claim Fee Allocation to Referrer

medium

Incompatibility with Fee-on-Transfer ERC20 Tokens in allocate

Aug '24

Rumpel Point Tokenization Protocol

Rumpel Point Tokenization Protocol

4.17 USDC • Sherlock • Galturok

#27

Fjord Token Staking

Fjord Token Staking

94.87 USDC • 2 total findings • CodeHawks • galturok

#16

medium

[H-01] Auction tokens will be lost forever when auction ends without bids

medium

Epoch mismatch in FjordPoints and FjordStaking leads to user being able to stake and unstake instantly for rewards

Winnables Raffles

Winnables Raffles

6.39 USDC • 3 total findings • Sherlock • Galturok

#29

high

Refund Actions Will Inadvertently Lock Contract Owners' ETH

high

Malicious Users Will Block Raffle Winners from Claiming Prizes in WinnablesTicketManager

medium

Role Management Flaw Grants Permanent Access to Users

Tadle

Tadle

0.07 USDC • 2 total findings • CodeHawks • galturok

#156

high

TokenManager - Unlimited withdraw

medium

Unnecessary balance checks and precision issues in TokenManager::_transfer

Jul '24

Basin

Basin

8.44 USDC • 1 total finding • Code4rena • TheFabled

#11

high

Incorrectly assigned `decimal1` parameter upon decoding

May '24

Beanstalk: The Finale

Beanstalk: The Finale

148.61 USDC • 1 total finding • CodeHawks • galturok

#29

medium

Improper Domain Separator Hash in _domainSeparatorV4() Function

Munchables

Munchables

0.01 USDC • 1 total finding • Code4rena • TheFabled

#16

high

Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens

LoopFi

LoopFi

213.33 USDC • 1 total finding • Code4rena • TheFabled

#5

high

Availability of deposit invariant can be bypassed

Apr '24

Renzo

Renzo

2.7 USDC • 2 total findings • Code4rena • TheFabled

#51

high

Incorrect withdraw queue balance in TVL calculation

medium

Withdrawals and Claims are meant to be pausable, but it is not possible in practice

DYAD

DYAD

750.33 USDC • 3 total findings • Code4rena • TheFabled

#9

high

Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral

high

Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply

high

Flash loan protection mechanism can be bypassed via self-liquidations