https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/5d7433d9-50bf-41c6-8f26-054f92610719.jpg

GiuseppeDeLaZara

Security Researcher

Ex-Petroleum Engineer | Solidity Developer & Security Researcher šŸŽÆ Managed DeFi projects holding millions in TVL šŸ“© DM for Partnerships | Security Reviews

Contact Me

High

13

Total

Medium

6

Solo

15

Total

$29.35K

Total Earnings

#291 All Time

8x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

4x

Top 10

All

Sherlock

Code4rena

Apr '24

DYAD

DYAD

8.69 USDC • 2 total findings • Code4rena • windhustler

#93

high

Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply

medium

Value of kerosene can be manipulated to force liquidate users

Feb '24

Tapioca

Tapioca

9,808.37 USDC • 11 total findings • Sherlock • GiuseppeDeLaZara

#6

high

TOFT can be forcefully unwrapped resulting in long-term DoS

high

Pending allowances can be exploited

high

All ETH can be stolen during rebalancing for `mTOFTs` that hold native

medium

`TOFTMarketReceiverModule::marketBorrowReceiver` flow is broken

medium

Pausable is not implemented

medium

Composing approval with other messages is subject to DoS

medium

StargateRouter cannot send payloads and rebalancing of ERC20s is broken

medium

`mTOFT` can be forced to receive the wrong ERC20 leading to token lockup

medium

Stargate Pools conversion rate leads to token accumulation inside the Balancer contract

medium

Gas parameters for Stargate swap are hardcoded leading to stuck messages

medium

`LeverageExecutor` is not working inside `BBLeverage` and `SGLeverage`

Jan '24

Decent

Decent

3,078.89 USDC • 3 total findings • Code4rena • windhustler

gold

high

Due to missing checks on minimum gas passed through LayerZero, executions can fail on the destination chain

medium

Potential loss of capital due to fixed fee calculations

medium

Permanent loss of tokens if swap data gets outdated

Oct '23

ENS

ENS

102.56 USDC • Code4rena • windhustler

#8

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

145.41 USDC • 3 total findings • Code4rena • windhustler

#35

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

medium

Message channels can be blocked resulting in DoS

medium

If RootBridgeAgent.lzReceiveNonBlocking reverts internally, the native token sent by relayer to RootBridgeAgent is left in RootBridgeAgent

Aug '23

veRWA

veRWA

9.82 USDC • Code4rena • windhustler

#52

Jul '23

Tapioca DAO

Tapioca DAO

16,166.83 USDC • 9 total findings • Code4rena • windhustler

bronze

high

Refund mechanism for failed cross-chain transactions does not work

high

Attacker can block LayerZero channel due to missing check of minimum gas passed

high

Attacker can block LayerZero channel due to variable gas cost of saving payload

high

TOFT `triggerSendFrom` can be used to steal all the balance

high

TOFT `removeCollateral` can be used to steal all the balance

high

TOFT `exerciseOption` can be used to steal all underlying erc20 tokens

high

TOFT leverageDown always fails if TOFT is a wrapper for native tokens

medium

TOFT `exerciseOption` fails due to not passing `msg.value` properly

medium

Airdropped tokens can be stolen by a bot

Apr '22

Phuture Finance contest

Phuture Finance contest

29.76 USDC • Code4rena • windhustler

#32