https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/e4094fa4-3db5-4831-93af-28a9ff063e74.png

J4X_

Security Researcher

Contact Me

High

22

Total

Medium

1

Solo

70

Total

$171.93K

Total Earnings

#58 All Time

19x

Payouts

gold

4x

1st Places

silver

1x

2nd Places

bronze

3x

3rd Places

All

Sherlock

Code4rena

Cantina

Hats Finance

Oct '24

tensor-monorepo

tensor-monorepo

9,029.84 USDC • 2 total findings • Cantina • J4X98

#6

medium

Finding not yet public.

medium

Finding not yet public.

Sep '24

infinitypools

infinitypools

1,592.99 USDC • 1 total finding • Cantina • J4X98

#13

high

Finding not yet public.

Aug '24

Centrifuge

Centrifuge

70,209.75 USDC • 27 total findings • Cantina • J4X98

gold

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

Metrom backend

Metrom backend

22,000 USDC • Hats • J4X

gold

Jun '24

grass

grass

6,355.65 USDC • 12 total findings • Cantina • J4X98

gold

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Andromeda – Validator Staking ADO and Vesting ADO

Andromeda – Validator Staking ADO and Vesting ADO

12,998.29 USDC • 8 total findings • Sherlock • J4X_

bronze

medium

Attacker can freeze users first rewards

medium

Un-bonding will lead to staked tokens getting stuck

medium

Rewards will get stuck if `withdrawaddrenabled` is set to false on the target chain

medium

Changes of the `UnbondingTime` are not accounted for

medium

Slashing allows users to bypass the lockup period of vestings

medium

Slashing of Unbondings is not accounted for and can lead to DOS of withdrawals

medium

Staked tokens will get stuck after claim

medium

Batch creation will break if vestings are opened to recipients

May '24

YOLO Games

YOLO Games

2,238.22 USDC • 3 total findings • Cantina • J4X98

bronze

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

safe-extensions

safe-extensions

4,326.86 USDC • 2 total findings • Cantina • J4X98

#5

medium

Finding not yet public.

medium

Finding not yet public.

Feb '24

opal-contracts

opal-contracts

1,780.66 USDC • 10 total findings • Cantina • J4X98

#6

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

HydraDX

HydraDX

23,597.19 USDC • 7 total findings • Code4rena • J4X

gold

medium

Malicious liquidity provider can put pool into highly manipulatable state

medium

Users can MAKE EMA-Oracle price outdated with direct transfers to StableSwap

medium

a huge loss of funds for all the users who try to remove liquidity after swapping got disabled at manipulated price .

medium

Missing hook call will lead to incorrect oracle results

medium

Storage can be bloated with low value liquidity positions

medium

[M02] Complete liquidity removals fail from stableswap pools

medium

[M09] No slippage check in `remove_liquidity` function in omnipool can lead to slippage losses during liquidity withdrawal.

Jan '24

Salty.IO

Salty.IO

811.39 USDC • 12 total findings • Code4rena • J4X

#18

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

high

The use of spot price by CoreSaltyFeed can lead to price manipulation and undesired liquidations

high

First Liquidity provider can claim all initial pool rewards

medium

THE USER WHO WITHDRAWS LIQUIDITY FROM A PARTICULAR POOL IS ABLE TO CLAIM MORE REWARDS THAN HE DULY DESERVES BY CAREFULLY SELECTING A `decreaseShareAmount` VALUE SUCH THAT THE `virtualRewardsToRemove` IS ROUNDED DOWN TO ZERO

medium

Chainlink price feed uses BTC, not WBTC. In case of depegging, oracles will become easier to manipulate.

medium

DOS of proposals by abusing ballot names without important parameters

medium

SALT staker can get extra voting power by simply unstaking their xSALT

medium

Remove Liquidity has missing reserve1 DUST check, which can make reserve1 to be less than DUST

medium

Impossible to change managed wallets with `proposeWallets` after first rejection

medium

Reusing a SALT that has already been used for voting can allow a malicious proposal to pass and compromise the protocol.

medium

If there is only one USDS borrower, he can never be liquidated

medium

Creation of token whitelisting proposals can be DOS'd

reNFT

reNFT

223.93 USDC • Code4rena • J4X

#34

Nov '23

metamorpho-and-periphery

metamorpho-and-periphery

12,357.39 USDC • 2 total findings • Cantina • J4X98

silver

medium

Finding not yet public.

medium

Finding not yet public.

Oct '23

Party Protocol

Party Protocol

168.15 USDC • 1 total finding • Code4rena • J4X

#24

medium

ETHCrowdfundBase.sol#processContribution - Impossible to finalize crowdfund because of minContribution check

Ethena Labs

Ethena Labs

218.85 USDC • 1 total finding • Code4rena • J4X

#18

medium

``FULL_RESTRICTED`` Stakers can bypass restriction through approvals

The Wildcat Protocol

The Wildcat Protocol

352.21 USDC • 1 total finding • Code4rena • J4X

#26

medium

Protocol markets are incompatible with rebasing tokens

ENS

ENS

1,840.73 USDC • 1 total finding • Code4rena • J4X

bronze

medium

Some tokens enable the direct draining of all approved `ERC20Votes` tokens

Sep '23

Venus Prime

Venus Prime

163.77 USDC • Code4rena • J4X

#24

Centrifuge

Centrifuge

1,663.91 USDC • 2 total findings • Code4rena • J4X

#6

medium

Investors claiming their maxDeposit by using the LiquidityPool.deposit() will cause that other users won't be able to claim their maxDeposit/maxMint

medium

The Restriction Manager does not completely implement ERC1404 which leads to account that are supposed to be restricted actually have access to do with their tokens as they see fit