https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_8.png

JohnSmith

Security Researcher

Contact Me

High

7

Total

Medium

17

Total

$5.28K

Total Earnings

#734 All Time

20x

Payouts

regular

5x

Top 10

regular

11x

Top 25

regular

14x

Top 50

All

Sherlock

Code4rena

Mar '24

Axis Finance

Axis Finance

5.04 USDC • 1 total finding • Sherlock • JohnSmith

#28

high

`RoutingParams` stored at wrong index breaks lot creation functionality

Revert Lend

Revert Lend

70.67 USDC • 3 total findings • Code4rena • JohnSmith

#51

high

Owner of a position can prevent liquidation due to the 'onERC721Received' callback

medium

Repayments and liquidations can be forced to revert by an attacker that repays miniscule amount of shares

medium

Users can lend and borrow above allowed limitations

Feb '24

Spectra

Spectra

107.43 USDC • 1 total finding • Code4rena • JohnSmith

#13

medium

PrincipalToken is not ERC-5095 compliant

Althea Liquid Infrastructure

Althea Liquid Infrastructure

329.85 USDC • 3 total findings • Code4rena • JohnSmith

#9

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

medium

`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.

medium

Withdrawal from NFTs can be temporarily blocked

Nov '22

Redacted Cartel contest

Redacted Cartel contest

118.46 USDC • 1 total finding • Code4rena • JohnSmith

#37

high

Underlying assets stealing in `AutoPxGmx` and `AutoPxGlp` via share price manipulation

Oct '22

Illuminate

Illuminate

49.19 USDC • 1 total finding • Sherlock • JohnSmith

#25

medium

Can not change fee used in Redeemer

NFTPort

NFTPort

252.99 USDC • 2 total findings • Sherlock • JohnSmith

#8

medium

Possible overflow in `royaltyInfo()`

medium

Vulnerable to cross-chain replay attacks

Mycelium

Mycelium

99.78 USDC • 1 total finding • Sherlock • JohnSmith

#9

high

First user can steal everyone else's tokens via share price manipulation and frontrunning

Sep '22

VTVL contest

VTVL contest

177.69 USDC • 2 total findings • Code4rena • JohnSmith

#34

medium

not able to create claim

medium

Variable balance token causing fund lock and loss

Harpie

Harpie

472.45 USDC • 3 total findings • Sherlock • JohnSmith

#4

medium

`changeRecipientAddress` susceptible to replay attacks

medium

Vault is Not Compatible with Fee Tokens

medium

Usage of deprecated `transfer` to send ETH

Aug '22

Sentiment

Sentiment

1,804.02 USDC • 4 total findings • Sherlock • JohnSmith

#11

high

ERC4626 Oracle may return incorrect price

high

Denial of Service by well funded first user

medium

Oracle data feed is insufficiently validated

medium

LToken vault is Not Compatible with Fee Tokens

Nouns DAO contest

Nouns DAO contest

133.27 USDC • Code4rena • JohnSmith

#16

FIAT DAO veFDT contest

FIAT DAO veFDT contest

557.33 USDC • 2 total findings • Code4rena • JohnSmith

#9

medium

ERROR IN UPDATING **_checkpoint** IN THE **increaseUnlockTime** FUNCTION

medium

Attacker contract can avoid being blocked by BlockList.sol

Mimo August 2022 contest

Mimo August 2022 contest

275.36 USDC • Code4rena • JohnSmith

#18

Jul '22

Golom contest

Golom contest

554.22 USDC • Code4rena • JohnSmith

#21

Yield Witch v2 contest

Yield Witch v2 contest

17.03 USDC • Code4rena • JohnSmith

#51

ENS contest

ENS contest

119.4 USDC • Code4rena • JohnSmith

#51

Juicebox V2 contest

Juicebox V2 contest

38.83 USDC • Code4rena • JohnSmith

#60

Jun '22

Putty contest

Putty contest

70.3 USDC • Code4rena • JohnSmith

#61

Nibbl contest

Nibbl contest

28.39 USDC • Code4rena • JohnSmith

#58