https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/13013498-6010-460e-b40c-6b858f3e1077.jpg

HonorLt

Security Researcher

A pleb💻

Contact Me

High

31

Total

Medium

34

Total

$11.88K

Total Earnings

#491 All Time

26x

Payouts

regular

12x

Top 10

regular

22x

Top 25

regular

25x

Top 50

All

Sherlock

Jul '24

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

230.14 USDC • 3 total findings • Sherlock • HonorLt

#15

high

Notify bribes about deposit will revert breaking the voting

medium

Incorrect operator authorization

medium

Renewing position harvests rewards to the operator

Mar '24

Zap Protocol

Zap Protocol

25.12 USDC • 2 total findings • Sherlock • HonorLt

#10

high

Incorrect claim index and update

medium

Native token vesting is not supported

Jan '24

Telcoin Platform Audit

Telcoin Platform Audit

2.64 USDC • 1 total finding • Sherlock • HonorLt

#9

high

Wrong burn logic

Truflation

Truflation

90.28 USDC • 1 total finding • Sherlock • HonorLt

#9

high

Unlimited claim of initial release

SYMM IO

SYMM IO

206.22 USDC • Sherlock • HonorLt

#8

May '23

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

0.00 USDC • 4 total findings • Sherlock • HonorLt

#94

high

No slippage protection

high

Wrong addresses configuration

high

Unprotected mint and burn

medium

Chainlink stale data

Apr '23

Blueberry Update

Blueberry Update

60.64 USDC • 1 total finding • Sherlock • HonorLt

#12

medium

Repay and liquidate race after unpausing

Teller

Teller

236.62 USDC • 4 total findings • Sherlock • HonorLt

#24

high

Unprotected commit collateral

medium

Fee changes affect pending bids

medium

Escrow does not handle fee on transfer tokens

medium

Loop gas limit

Mar '23

Y2K

Y2K

1,201.36 USDC • 3 total findings • Sherlock • HonorLt

#14

high

DOS queue minting of shares

high

Enlisting in rollover might assign a wrong index

medium

Change of treasury whitelists and sets different variables

Taurus

Taurus

30.89 USDC • 1 total finding • Sherlock • HonorLt

#12

medium

Mint limit is not reduced when the Vault is burning TAU

Feb '23

Derby

Derby

1,322.71 USDC • 6 total findings • Sherlock • HonorLt

#10

high

Not all providers claim the rewards

medium

Unnecessary allowance when swapping rewards

medium

Hardcoded WETH

medium

Wrong assumption that stablecoins are always equal in price

medium

Protocols dependence on each other

medium

withdrawal request override

OlympusDAO

OlympusDAO

56.54 USDC • 1 total finding • Sherlock • HonorLt

#31

medium

Removal of tokens discards accrued rewards

Fair Funding by Alchemix & Unstoppable

Fair Funding by Alchemix & Unstoppable

34.48 USDC • 1 total finding • Sherlock • HonorLt

#8

medium

Anyone can mint the first token and start the auction

Carapace

Carapace

18.81 USDC • 1 total finding • Sherlock • HonorLt

#34

high

Repeated requests of withdrawal

Blueberry

Blueberry

14.61 USDC • 1 total finding • Sherlock • HonorLt

#35

medium

Chainlink stale data

OpenQ

OpenQ

385.08 USDC • 7 total findings • Sherlock • HonorLt

#19

high

Dependant token transfers can block claims

high

Refunds after close can trick the claims

high

One refund can break the bounty

high

Many deposits can block refunds

medium

Token limit might be artificially reached

medium

Impossible to reduce the size of payout schedule

medium

Locked funds do not account for claims and refunds

Jan '23

Cooler

Cooler

352.53 USDC • 4 total findings • Sherlock • HonorLt

#7

high

Unlimited rolls

high

Fully repaid debt tokens do not reach the lender

high

Transfer return values

medium

Loan is rollable by default

UXD Protocol

UXD Protocol

1,628.49 USDC • 4 total findings • Sherlock • HonorLt

#8

high

TWAP value is not reliable

high

Rebalance with any account

medium

Redeem depository search does not account for amount

medium

Vulnerable GovernorVotesQuorumFraction version

Nov '22

Opyn Crab Netting

Opyn Crab Netting

146.18 USDC • 2 total findings • Sherlock • HonorLt

#18

high

Unprotected checkOrder

medium

FILO can cause DOS

Isomorph

Isomorph

2,692.69 USDC • 3 total findings • Sherlock • HonorLt

#5

high

Anyone can withdraw approved tokens from gauge

high

Changes in system parameters might hurt existing users

medium

Missing or not entirely correct validations

Buffer Finance

Buffer Finance

543.41 USDC • 2 total findings • Sherlock • HonorLt

#8

medium

Support of various tokens

medium

Re-entrancy protection

Oct '22

Illuminate

Illuminate

1,640.42 USDC • 5 total findings • Sherlock • HonorLt

#8

high

Lend or mint after maturity

high

Unpaused on redeem functions

high

User controlled parameters and re-entrancy

high

Mint Illuminate's ERC5095 indefinitely and auto redeem

medium

Incorrect parameters

Astaria

Astaria

365.96 USDC • 3 total findings • Sherlock • HonorLt

#17

high

ecrecover returns zero address for invalid signatures

high

commitToLiens via AstariaRouter will not work

medium

Strategist nonce replay

Merit Circle

Merit Circle

257.01 USDC • 1 total finding • Sherlock • HonorLt

#9

high

Increasing the lock malfunction

Sep '22

Harpie

Harpie

116.84 USDC • 2 total findings • Sherlock • HonorLt

#14

medium

Support of weird ERC20s

medium

Unbounded fee

Aug '22

Sentiment

Sentiment

223.03 USDC • 2 total findings • Sherlock • HonorLt

#21

medium

Cannot repay the native asset

medium

Missing validations