Security Researcher
High
Total
Medium
Total Earnings
#377 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Mar '23
329.30 USDC • Sherlock • Jujic
#11
Jan '23
25.33 USDC • 1 total finding • Code4rena • Jujic
#57
medium
Lack of support for fee-on-transfer token
Oct '22
34.01 USDC • 2 total findings • Code4rena • Jujic
#44
Protocol withdrawals of collateral can be unexpectedly locked if governance sets the `collateralFactorBps` to 0.
Chainlink oracle data feed is not sufficiently validated and can return stale `price`
26.35 USDC • Code4rena • Jujic
#39
20.79 USDC • Code4rena • Jujic
#16
Sep '22
60.77 USDC • Code4rena • Jujic
#97
Aug '22
11.03 USDC • 1 total finding • Code4rena • Jujic
#92
[NAZ-M1] Chainlink's `latestRoundData` Might Return Stale Results
40.62 USDC • Code4rena • Jujic
#68
Jul '22
35.32 USDC • Code4rena • Jujic
#85
5.45 USDC • 1 total finding • Code4rena • Jujic
#71
transfer() depends on gas consts
Jun '22
145.65 USDC • Code4rena • Jujic
#49
Apr '22
91.37 USDC • Code4rena • Jujic
#53
1,241.61 USDC • 2 total findings • Code4rena • Jujic
#13
Chainlink pricer is using a deprecated API
Oracle data feed is insufficiently validated.
Mar '22
586.89 USDC • Code4rena • Jujic
#8
934.14 USDC • 1 total finding • Code4rena • Jujic
Add a timelock to PaladinRewardReserve functions
694.4 USDC • 2 total findings • Code4rena • Jujic
#25
WithdrawFacet's withdraw calls native payable.transfer, which can be unusable for DiamondStorage owner contract
Reputation Risks with `contractOwner`
48.52 USDC • Code4rena • Jujic
#31
182.94 USDT • 1 total finding • Code4rena • Jujic
#37
Incompatibility With Rebasing/Deflationary/Inflationary token
Feb '22
227.49 USDC • Code4rena • Jujic
#29
277.46 USDC • 1 total finding • Code4rena • Jujic
#21
Send ether with call instead of transfer.
564.53 USDC • Code4rena • Jujic
40.51 USDC • Code4rena • Jujic
#30
437.4 USDC • 2 total findings • Code4rena • Jujic
#27
Owner can lock tokens in `MasterChef`
[ConcurRewardPool] Possible reentrancy when claiming rewards
Jan '22
1,631.82 USDC • 1 total finding • Code4rena • Jujic
No upper limit on `coolDownTimeInSeconds` allows funds to be locked sNOTE owner.
8.37 USDC • Code4rena • Jujic
1,616.67 USDT • 1 total finding • Code4rena • Jujic
#9
Improper Upper Bound Definition on the Fee
213.59 USDC • Code4rena • Jujic
358.43 USDC • Code4rena • Jujic
#17
92.63 tokens) • Code4rena • Jujic
349.03 tokens) • Code4rena • Jujic
#22
97.53 USDC • Code4rena • Jujic
#20
77.58 USDC • Code4rena • Jujic
Dec '21
109.45 USDC • Code4rena • Jujic
#14
1,392.9 USDC • Code4rena • Jujic
#12
336.92 USDC • Code4rena • Jujic
51.14 USDC • Code4rena • Jujic
#23
1,213.36 USDC • 1 total finding • Code4rena • Jujic
#10
Missing approve(0)
65.95 ETH • Code4rena • Jujic
260.27 USDC • Code4rena • Jujic
Nov '21
3,528.88 USDC • 1 total finding • Code4rena • Jujic
high
Improper implementation of `arbitraryCall()` allows protocol gov to steal funds from users' wallets
405.5 USDC • Code4rena • Jujic