https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

Josiah

Security Researcher

Contact Me

High

6

Total

Medium

16

Total

$8.91K

Total Earnings

#618 All Time

37x

Payouts

regular

5x

Top 10

regular

16x

Top 25

regular

28x

Top 50

All

Code4rena

Jun '23

Stader Labs

Stader Labs

0 USDC • 1 total finding • Code4rena • Josiah

#37

medium

no bidder has incentive to bid the Auction except doing last-minute MEV due to fixed endBlock

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

240.03 USDC • 1 total finding • Code4rena • Josiah

#50

medium

Unstaking `vMAIA` tokens on the first Tuesday of the month can be offset

Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

51.68 USDC • 1 total finding • Code4rena • Josiah

#43

medium

Exchange Rate can be manipulated

Apr '23

EigenLayer Contest

EigenLayer Contest

2,109.36 USDC • 1 total finding • Code4rena • Josiah

#8

medium

A staker with verified over-commitment can potentially bypass slashing completely

ENS Contest

ENS Contest

59.79 USDC • Code4rena • Josiah

#20

Frankencoin

Frankencoin

36.76 USDC • 1 total finding • Code4rena • Josiah

#61

medium

POSITION LIMIT COULD BE FULLY REDUCED TO ZERO BY CLONES

Caviar Private Pools

Caviar Private Pools

80.67 USDC • 2 total findings • Code4rena • Josiah

#49

medium

Incorrect protocol fee is taken when changing NFTs

medium

Flash loan fee is incorrect in Private Pool contract

Rubicon v2

Rubicon v2

0.44 USDC • 1 total finding • Code4rena • Josiah

#122

medium

Calling `Position._marketBuy` and `Position._marketSell` functions that calculate `_fee` by dividing by `10000` can cause incorrect calculations

Mar '23

Asymmetry contest

Asymmetry contest

42.06 USDC • Code4rena • Josiah

#83

Polynomial Protocol contest

Polynomial Protocol contest

1,201.95 USDC • Code4rena • Josiah

#11

Neo Tokyo contest

Neo Tokyo contest

154.74 USDC • 1 total finding • Code4rena • Josiah

#18

high

Underflow of `lpPosition.points` during withdrawLP causes huge reward minting

Feb '23

Ethos Reserve contest

Ethos Reserve contest

61.26 USDC • Code4rena • Josiah

#33

Jan '23

Popcorn contest

Popcorn contest

23.45 USDC • 2 total findings • Code4rena • Josiah

#85

high

First vault depositor can steal other's assets

medium

Fee on transfer token not supported

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

26.84 USDC • 2 total findings • Code4rena • Josiah

#64

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts

medium

Users may not claim Erc1155 rewards when the Quest has ended

Timeswap contest

Timeswap contest

65.35 USDC • Code4rena • Josiah

#20

OpenSea Seaport 1.2 contest

OpenSea Seaport 1.2 contest

140.67 USDC • Code4rena • Josiah

#9

Ondo Finance contest

Ondo Finance contest

304.58 USDC • Code4rena • Josiah

#14

Astaria contest

Astaria contest

69.09 USDC • 1 total finding • Code4rena • Josiah

#51

high

ERC4626Cloned deposit and mint logic differ on first deposit

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

36.5 USDC • Code4rena • Josiah

#55

Dec '22

GoGoPool contest

GoGoPool contest

484.34 USDC • 1 total finding • Code4rena • Josiah

#37

high

node operator is getting slashed for full duration even though rewards are distributed based on a 14 day cycle

Escher contest

Escher contest

991.64 USDC • 1 total finding • Code4rena • Josiah

#9

medium

`buy()` in `LPDA.sol` Can be Manipulated by Buyers

Maverick contest

Maverick contest

59.84 USDC • Code4rena • Josiah

#13

Nov '22

ParaSpace contest

ParaSpace contest

292.01 USDC • 2 total findings • Code4rena • Josiah

#37

high

Data corruption in NFTFloorOracle; Denial of Service

medium

Centralization risk: admin can with rug the project by removing asset and price manipulation on oracle.

Canto contest

Canto contest

59.89 CANTO • Code4rena • Josiah

#11

Redacted Cartel contest

Redacted Cartel contest

53.49 USDC • Code4rena • Josiah

#46

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

58.28 USDC • 1 total finding • Code4rena • Josiah

#51

medium

Calling `updateNodeRunnerWhitelistStatus` function always reverts

Blur Exchange contest

Blur Exchange contest

548.16 USDC • 1 total finding • Code4rena • Josiah

#14

medium

Hacked owner or malicious owner can immediately steal all assets on the platform

LooksRare Aggregator contest

LooksRare Aggregator contest

330.18 USDC • Code4rena • Josiah

#10

SIZE contest

SIZE contest

720.22 USDC • 1 total finding • Code4rena • Josiah

#6

medium

Incompatibility with fee-on-transfer/inflationary/deflationary/rebasing tokens, on both base tokens and quote tokens, with varying impacts

Debt DAO contest

Debt DAO contest

61.35 USDC • Code4rena • Josiah

#51

Chainlink Staking contest

Chainlink Staking contest

192.86 USDC • Code4rena • Josiah

#16

Oct '22

Paladin - Warden Pledges contest

Paladin - Warden Pledges contest

180.64 USDC • Code4rena • Josiah

#25

Inverse Finance contest

Inverse Finance contest

36.73 USDC • Code4rena • Josiah

#43

Holograph contest

Holograph contest

55.67 USDC • Code4rena • Josiah

#37

3xcalibur contest

3xcalibur contest

34.98 USDC • Code4rena • Josiah

#33

Trader Joe v2 contest

Trader Joe v2 contest

0.01 USDC • 1 total finding • Code4rena • Josiah

#33

medium

Very critical `Owner` privileges can cause complete destruction of the project in a possible privateKey exploit

The Graph L2 bridge contest

The Graph L2 bridge contest

50.28 USDC • Code4rena • Josiah

#15