https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/8ebc90c3-ed02-402f-a296-3bff62eb6cbb.jpeg

JCN

Security Researcher

Learning

Contact Me

High

20

Total

Medium

22

Total

$83.47K

Total Earnings

#100 All Time

35x

Payouts

silver

1x

2nd Places

bronze

1x

3rd Places

regular

8x

Top 10

All

Sherlock

Code4rena

Cantina

Immunefi

Jan '25

Next Generation

Next Generation

487.39 USDC • 2 total findings • Code4rena • JCN

bronze

high

Cross-Chain Signature Replay Attack Due to User-Supplied `domainSeparator` and Missing Deadline Check

medium

ERC-20 Allowance Bypass: Spender Can Force Sender to Pay Extra Fees Beyond Approved Amount

Liquid Ron

Liquid Ron

0.03 USDC • 2 total findings • Code4rena • JCN

#10

high

The calculation of `totalAssets()` could be wrong if `operatorFeeAmount` > 0, this can cause potential loss for the new depositors

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

silo-contracts-v2

silo-contracts-v2

8,437.53 USDC • 3 total findings • Cantina • 0xJCN

#8

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Dec '24

story-protocol

story-protocol

28,517.35 USDC • 4 total findings • Cantina • 0xJCN

#10

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Aug '24

ZeroLend One

ZeroLend One

948.30 USDC • 7 total findings • Sherlock • JCN

#14

high

Faulty debt balance calculation prevents users from repaying their debt

high

Violators will continue to earn rewards on their outdated debt balance post liquidation

high

Debt shares are mistaken for debt assets during liquidations

high

Pending interest from pools not accounted for during vault operations

high

Interest rates are severely underestimated after every liquidation

high

Interest rates are overestimated after every repayment

medium

Repayments via the `NFTPositionManager` will be blocked for reserves that have pending interest

Jul '24

Audit Comp | Folks Finance

Audit Comp | Folks Finance

5,217 USDC • 6 total findings • Immunefi • JCN2023

#7

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jun '24

Size

Size

307.12 USDC • 1 total finding • Code4rena • JCN

#39

medium

Size uses wrong source to query available liquidity on Aave, resulting in borrow and lend operations being bricked upon mainnet deployment

May '24

Euler-v2

Euler-v2

10,714 USDC • Cantina • 0xJCN

#13

Mar '24

Revert Lend

Revert Lend

713.13 USDC • 2 total findings • Code4rena • JCN

#21

medium

Repayments and liquidations can be forced to revert by an attacker that repays miniscule amount of shares

medium

Users' newly created positions can be prematurely closed and removed from the vault directly after they are created

Feb '24

curvance

curvance

10,242.62 USDC • 6 total findings • Cantina • 0xJCN

#13

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Wise Lending

Wise Lending

3,299.91 USDC • 1 total finding • Code4rena • JCN

#12

high

Incorrect bad debt accounting can lead to a state where the `claimFeesBeneficial` function is permanently bricked and no new incentives can be distributed, potentially locking pending and future protocol fees in the `FeeManager` contract

AI Arena

AI Arena

1.64 USDC • 2 total findings • Code4rena • JCN

#162

high

Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes

medium

NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)

Jan '24

reNFT

reNFT

87.86 USDC • Code4rena • JCN

#41

Dec '23

Ethereum Credit Guild

Ethereum Credit Guild

4,768.39 USDC • 6 total findings • Code4rena • JCN

silver

high

The userGaugeProfitIndex is not set correctly, allowing an attacker to receive rewards without waiting

high

Users staking via the `SurplusGuildMinter` can be immediately slashed when staking into a gauge that had previously incurred a loss

high

The creation of bad debt (`mark-down` of Credit) can force other loans in auction to also create bad debt

medium

Over 90% of the Guild staked in a gauge can be unstaked, despite the gauge utilizing its full debt allocation

medium

Incorrect calculations in debtCeiling

medium

Malicious borrower can decrease Guild holders reward

Nov '23

Audit Comp | DeGate

Audit Comp | DeGate

2,500 USDC • 1 total finding • Immunefi • JCN2023

#8

low

Finding not yet public.

Jul '23

Basin

Basin

58.47 USDC • Code4rena • JCN

#24

Nouns DAO

Nouns DAO

605.89 USDC • Code4rena • JCN

#11

Jun '23

Lybra Finance

Lybra Finance

104.56 USDC • Code4rena • JCN

#55

Llama

Llama

361.13 USDC • Code4rena • JCN

#14

Stader Labs

Stader Labs

330.02 USDC • Code4rena • JCN

#23

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

610.33 USDC • Code4rena • JCN

#40

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

59.42 USDC • Code4rena • JCN

#43

Juicebox Buyback Delegate

Juicebox Buyback Delegate

305.76 USDC • Code4rena • JCN

#14

Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

821.24 USDC • Code4rena • JCN

#19

Ajna Protocol

Ajna Protocol

233.79 USDC • Code4rena • JCN

#35

Apr '23

ENS Contest

ENS Contest

988.86 USDC • Code4rena • JCN

#13

Frankencoin

Frankencoin

273.34 USDC • Code4rena • JCN

#28

Caviar Private Pools

Caviar Private Pools

624.02 USDC • Code4rena • JCN

#13

Rubicon v2

Rubicon v2

348.26 USDC • Code4rena • JCN

#36

Mar '23

Asymmetry contest

Asymmetry contest

90.74 USDC • Code4rena • JCN

#55

Canto Identity Subprotocols contest

Canto Identity Subprotocols contest

77.59 USDC • Code4rena • JCN

#22

Neo Tokyo contest

Neo Tokyo contest

194.86 USDC • Code4rena • JCN

#14

Wenwin contest

Wenwin contest

81.41 USDC • Code4rena • JCN

#24

Aragon Protocol contest

Aragon Protocol contest

747.74 USDC • Code4rena • JCN

#9

Feb '23

Ethos Reserve contest

Ethos Reserve contest

308.79 USDC • Code4rena • JCN

#28