https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

KmanOfficial

Security Researcher

Contact Me

High

4

Total

Medium

8

Total

$351.00

Total Earnings

#1625 All Time

8x

Payouts

regular

4x

Top 50

All

Code4rena

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

25.73 USDC • 1 total finding • Code4rena • KmanOfficial

#32

medium

Distribution can be bricked, and double claims by a few holders are possible when owner calls `LiquidInfrastructureERC20::setDistributableERC20s`

AI Arena

AI Arena

10.15 USDC • 4 total findings • Code4rena • KmanOfficial

#123

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)

medium

DoS in `MergingPool::claimRewards` function and potential DoS in `RankedBattle::claimNRN` function if called after a significant amount of rounds passed.

Jan '24

Curves

Curves

3.82 USDC • 1 total finding • Code4rena • KmanOfficial

#111

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

Aug '23

Dopex

Dopex

32.67 USDC • 2 total findings • Code4rena • KmanOfficial

#100

medium

Inaccurate swap amount calculation in ReLP leads to stuck tokens and lost liquidity

medium

`sync` function in `RdpxV2Core.sol` should be called in multiple scenarios to account for the balance changes that occurs

veRWA

veRWA

31.42 USDC • 1 total finding • Code4rena • KmanOfficial

#46

high

Delegated votes are locked when owner lock is expired

Tangible Caviar

Tangible Caviar

84.76 USDC • Code4rena • KmanOfficial

#50

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

140.9 USDC • 2 total findings • Code4rena • KmanOfficial

#31

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`

medium

Funds can be stuck due to wrong order of operations

Dec '22

GoGoPool contest

GoGoPool contest

21.71 USDC • 1 total finding • Code4rena • KmanOfficial

#75

medium

Coding logic of the contract upgrading renders upgrading contracts impractical