Security Researcher
High
Total
Medium
Total Earnings
#714 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Mar '24
5.04 USDC • 1 total finding • Sherlock • JohnSmith
#28
high
`RoutingParams` stored at wrong index breaks lot creation functionality
70.67 USDC • 3 total findings • Code4rena • JohnSmith
#51
Owner of a position can prevent liquidation due to the 'onERC721Received' callback
medium
Repayments and liquidations can be forced to revert by an attacker that repays miniscule amount of shares
Users can lend and borrow above allowed limitations
Feb '24
107.43 USDC • 1 total finding • Code4rena • JohnSmith
#13
PrincipalToken is not ERC-5095 compliant
329.85 USDC • 3 total findings • Code4rena • JohnSmith
#9
Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions
`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.
Withdrawal from NFTs can be temporarily blocked
Nov '22
118.46 USDC • 1 total finding • Code4rena • JohnSmith
#37
Underlying assets stealing in `AutoPxGmx` and `AutoPxGlp` via share price manipulation
Oct '22
49.19 USDC • 1 total finding • Sherlock • JohnSmith
#25
Can not change fee used in Redeemer
252.99 USDC • 2 total findings • Sherlock • JohnSmith
#8
Possible overflow in `royaltyInfo()`
Vulnerable to cross-chain replay attacks
99.78 USDC • 1 total finding • Sherlock • JohnSmith
First user can steal everyone else's tokens via share price manipulation and frontrunning
Sep '22
177.69 USDC • 2 total findings • Code4rena • JohnSmith
#34
not able to create claim
Variable balance token causing fund lock and loss
472.45 USDC • 3 total findings • Sherlock • JohnSmith
#4
`changeRecipientAddress` susceptible to replay attacks
Vault is Not Compatible with Fee Tokens
Usage of deprecated `transfer` to send ETH
Aug '22
1,804.02 USDC • 4 total findings • Sherlock • JohnSmith
#11
ERC4626 Oracle may return incorrect price
Denial of Service by well funded first user
Oracle data feed is insufficiently validated
LToken vault is Not Compatible with Fee Tokens
133.27 USDC • Code4rena • JohnSmith
#16
557.33 USDC • 2 total findings • Code4rena • JohnSmith
ERROR IN UPDATING **_checkpoint** IN THE **increaseUnlockTime** FUNCTION
Attacker contract can avoid being blocked by BlockList.sol
275.36 USDC • Code4rena • JohnSmith
#18
Jul '22
554.22 USDC • Code4rena • JohnSmith
#21
17.03 USDC • Code4rena • JohnSmith
119.4 USDC • Code4rena • JohnSmith
38.83 USDC • Code4rena • JohnSmith
#60
Jun '22
70.3 USDC • Code4rena • JohnSmith
#61
28.39 USDC • Code4rena • JohnSmith
#58