Security Researcher
High
Total
Medium
Total Earnings
#212 All Time
Payouts
Top 10
Top 25
Top 50
All
Code4rena
Oct '22
0.33 USDC • 1 total finding • Code4rena • JMukesh
#31
high
Transfering funds to yourself increases your balance
Jun '22
28.29 USDC • Code4rena • JMukesh
#61
436.19 USDC • 1 total finding • Code4rena • JMukesh
#35
Anyone can set the `baseRatePerYear` after the `updateFrequency` has passed
163.33 USDC • Code4rena • JMukesh
#47
May '22
60.41 USDC • 2 total findings • Code4rena • JMukesh
#74
medium
Use `safeTransfer()`/`safeTransferFrom()` instead of `transfer()`/`transferFrom()`
Use `call()` instead of `transfer()` when transferring ETH in RubiconRouter
1,355.15 USDT • Code4rena • JMukesh
#21
Apr '22
259.27 USDC • 1 total finding • Code4rena • JMukesh
#28
Chainlink pricer is using a deprecated API
Mar '22
1,082.75 USDC • 2 total findings • Code4rena • JMukesh
#20
WithdrawFacet's withdraw calls native payable.transfer, which can be unusable for DiamondStorage owner contract
LibSwap: Excess funds from swaps are not returned
378.21 USDT • 1 total finding • Code4rena • JMukesh
#27
A `pauser` can brick the contracts
Dec '21
2,862.52 USDC • 2 total findings • Code4rena • JMukesh
#9
ERC20 return values not checked
Unchecked return value from low-level call()
Nov '21
81.35 ETH • 1 total finding • Code4rena • JMukesh
#12
Eth may get stuck in contract
707.6 USDC • Code4rena • JMukesh
#13
Oct '21
1,274.33 ETH • Code4rena • JMukesh
461.32 ETH • 1 total finding • Code4rena • JMukesh
#7
Swap.sol implements potentially dangerous transfer
27.68 USDC • Code4rena • JMukesh
#8
Sep '21
1,505.93 ETH • 1 total finding • Code4rena • JMukesh
Unsafe handling of underlying tokens
1,043.18 USDC • 2 total findings • Code4rena • JMukesh
Use safeTransfer instead of transfer
`burn` and `mintTo` in `Basket.sol` vulnerable to reentrancy
998.28 USDC • Code4rena • JMukesh
5,314.71 USDC • 1 total finding • Code4rena • JMukesh
#5
use of transfer() instead of call() to send eth
2,894.58 tokens) • Code4rena • JMukesh
Aug '21
5,666.24 USDC • 2 total findings • Code4rena • JMukesh
#6
Use of transfer() instead of call() to send eth
Missing validation on latestRoundData
381.01 USDC • Code4rena • JMukesh
2,217.98 tokens) • 2 total findings • Code4rena • JMukesh
#4
Unchecked ERC20 transfers can cause lock up
Uninitialized Variable `marketWhitelist` in `RCTreasury.sol`
707.33 USDC • 1 total finding • Code4rena • JMukesh
No ERC20 safe* versions called
922.45 USDC • Code4rena • JMukesh
Jul '21
310.48 USDC • Code4rena • JMukesh
#10
516.79 USDC • 1 total finding • Code4rena • JMukesh
Result of transfer / transferFrom not checked
1,470.21 USDC • 1 total finding • Code4rena • JMukesh
safeTransferFrom in TransferHelper is not safeTransferFrom
Jun '21
2,191.84 USDC • 1 total finding • Code4rena • JMukesh
No check transferFrom() return value
1,552.12 USDC • 1 total finding • Code4rena • JMukesh
Return values of ERC20 `transfer` and `transferFrom` are unchecked
395.58 USDC • 2 total findings • Code4rena • JMukesh
May '21
1,441.12 USDC • 1 total finding • Code4rena • JMukesh
1,086.18 USDC • Code4rena • JMukesh
0 USDC • Code4rena • JMukesh
891.75 USDC • 1 total finding • Code4rena • JMukesh
Randomization of NFTs returned in redeem/swap operations can be brute-forced
Apr '21
2,005.35 USDC • 1 total finding • Code4rena • JMukesh
instead of call() , transfer() is used to withdraw the ether
2,247.13 USDC • 1 total finding • Code4rena • JMukesh
Anyone Can Avoid All Vether Transfer Fees By Adding Their Address to the Vether ExcludedAddresses List.
775.86 USDC • Code4rena • JMukesh