https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/4a0d4a40-e9b6-4cfa-b236-381273c85823.png

KlosMitSoss

Security Researcher

Contact Me

High

5

Total

Medium

18

Total

$30.03K

Total Earnings

#271 All Time

9x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

bronze

2x

3rd Places

All

Sherlock

Code4rena

Cantina

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • KlosMitSoss

#18

medium

Attacker can repeatedly decrease the reward rate by adding tiny rewards causing a loss for existing stakers

Feb '25

Rova

Rova

1,178.25 USDC • 1 total finding • Sherlock • KlosMitSoss

silver

medium

The token amount accounting will be broken when a participation is updated

defi-app-contracts

defi-app-contracts

2,895.06 USDC • 3 total findings • Cantina • KlosMitSoss

bronze

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Jan '25

infrared-contracts

infrared-contracts

10,590.73 USDC • 6 total findings • Cantina • KlosMitSoss

#8

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Plaza Finance

Plaza Finance

0.23 USDC • 1 total finding • Sherlock • KlosMitSoss

#99

medium

Bidding will not be possible if the bidder with the lowest bid is blacklisted by USDC

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

2.85 USDC • 2 total findings • Sherlock • KlosMitSoss

#31

high

The graduator may not be able to withdraw funds from a graduated market which causes them to be stuck

medium

Missing slippage protection in `ReputationMarket::sellVotes()`

Debita Finance V3

Debita Finance V3

149.66 USDC • 4 total findings • Sherlock • KlosMitSoss

#21

medium

A malicious lender will cause lending offers to be unmatchable and uncancellable due to a missing check in `DLOImplementation::addFunds()`

medium

A lender can repeatedly change the perpetual status of a fully filled offer, making other offers unmatchable and non-cancelable.

medium

Precision loss leads to locked incentives in `DebitaIncentives::claimIncentives()`

medium

Malicious users will exploit the incentive mechanism rendering it useless

Oct '24

Ethos Network Social Contracts

Ethos Network Social Contracts

1,911.58 USDC • 2 total findings • Sherlock • KlosMitSoss

bronze

medium

Restored addresses will not be able to take any action on behalf of the profile due to still being marked as compromised

medium

A compromised address will still be able to take action on behalf of the profile after it has been deleted due to an insufficient check in `EthosProfile::verifiedProfileIdForAddress()``

Kleidi

Kleidi

13,298.28 USDC • 3 total findings • Code4rena • KlosMitSoss

gold

medium

Wrong handling of call data check indices, forcing it sometimes to revert

medium

Gas griefing/attack via creating the proposals

medium

UpdateExpirattionPeriod() cannot be execute when the newExpirationPeriod is less than currentExpirationPeriod.