Security Researcher
High
Total
Medium
Total Earnings
#618 All Time
Payouts
Top 10
Top 25
Top 50
All
Code4rena
Jun '23
0 USDC • 1 total finding • Code4rena • Josiah
#37
medium
no bidder has incentive to bid the Auction except doing last-minute MEV due to fixed endBlock
May '23
240.03 USDC • 1 total finding • Code4rena • Josiah
#50
Unstaking `vMAIA` tokens on the first Tuesday of the month can be offset
51.68 USDC • 1 total finding • Code4rena • Josiah
#43
Exchange Rate can be manipulated
Apr '23
2,109.36 USDC • 1 total finding • Code4rena • Josiah
#8
A staker with verified over-commitment can potentially bypass slashing completely
59.79 USDC • Code4rena • Josiah
#20
36.76 USDC • 1 total finding • Code4rena • Josiah
#61
POSITION LIMIT COULD BE FULLY REDUCED TO ZERO BY CLONES
80.67 USDC • 2 total findings • Code4rena • Josiah
#49
Incorrect protocol fee is taken when changing NFTs
Flash loan fee is incorrect in Private Pool contract
0.44 USDC • 1 total finding • Code4rena • Josiah
#122
Calling `Position._marketBuy` and `Position._marketSell` functions that calculate `_fee` by dividing by `10000` can cause incorrect calculations
Mar '23
42.06 USDC • Code4rena • Josiah
#83
1,201.95 USDC • Code4rena • Josiah
#11
154.74 USDC • 1 total finding • Code4rena • Josiah
#18
high
Underflow of `lpPosition.points` during withdrawLP causes huge reward minting
Feb '23
61.26 USDC • Code4rena • Josiah
#33
Jan '23
23.45 USDC • 2 total findings • Code4rena • Josiah
#85
First vault depositor can steal other's assets
Fee on transfer token not supported
26.84 USDC • 2 total findings • Code4rena • Josiah
#64
Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts
Users may not claim Erc1155 rewards when the Quest has ended
65.35 USDC • Code4rena • Josiah
140.67 USDC • Code4rena • Josiah
#9
304.58 USDC • Code4rena • Josiah
#14
69.09 USDC • 1 total finding • Code4rena • Josiah
#51
ERC4626Cloned deposit and mint logic differ on first deposit
36.5 USDC • Code4rena • Josiah
#55
Dec '22
484.34 USDC • 1 total finding • Code4rena • Josiah
node operator is getting slashed for full duration even though rewards are distributed based on a 14 day cycle
991.64 USDC • 1 total finding • Code4rena • Josiah
`buy()` in `LPDA.sol` Can be Manipulated by Buyers
59.84 USDC • Code4rena • Josiah
#13
Nov '22
292.01 USDC • 2 total findings • Code4rena • Josiah
Data corruption in NFTFloorOracle; Denial of Service
Centralization risk: admin can with rug the project by removing asset and price manipulation on oracle.
59.89 CANTO • Code4rena • Josiah
53.49 USDC • Code4rena • Josiah
#46
58.28 USDC • 1 total finding • Code4rena • Josiah
Calling `updateNodeRunnerWhitelistStatus` function always reverts
548.16 USDC • 1 total finding • Code4rena • Josiah
Hacked owner or malicious owner can immediately steal all assets on the platform
330.18 USDC • Code4rena • Josiah
#10
720.22 USDC • 1 total finding • Code4rena • Josiah
#6
Incompatibility with fee-on-transfer/inflationary/deflationary/rebasing tokens, on both base tokens and quote tokens, with varying impacts
61.35 USDC • Code4rena • Josiah
192.86 USDC • Code4rena • Josiah
#16
Oct '22
180.64 USDC • Code4rena • Josiah
#25
36.73 USDC • Code4rena • Josiah
55.67 USDC • Code4rena • Josiah
34.98 USDC • Code4rena • Josiah
0.01 USDC • 1 total finding • Code4rena • Josiah
Very critical `Owner` privileges can cause complete destruction of the project in a possible privateKey exploit
50.28 USDC • Code4rena • Josiah
#15