https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/02ca5744-0bf3-4f17-8267-034b6a75d0f5.png

Limbooo

Security Researcher

Web3 Security + Full Stack Developer. Hunting on @immunefi, @code4rena, @sherlockdefi

Contact Me

High

19

Total

Medium

31

Total

$16.12K

Total Earnings

#399 All Time

45x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

7x

Top 10

All

Sherlock

Code4rena

Cantina

Mar '25

tally-stGOV

tally-stGOV

1,062.99 USDC • 1 total finding • Cantina • Kasheeda

bronze

medium

Finding not yet public.

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • Limbooo

#18

medium

Attacker Can Disrupt Reward Periods to Reduce Legitimate Users' Rewards

Feb '25

size-solidity

size-solidity

171.52 USDC • 1 total finding • Cantina • Kasheeda

#4

medium

Finding not yet public.

THORWallet

THORWallet

0 USDC • 1 total finding • Code4rena • Limbooo

#10

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Rova

Rova

1,178.30 USDC • 2 total findings • Sherlock • Limbooo

gold

medium

Incorrect Token Allocation in `updateParticipation`

medium

Incorrect Token Limits Checks in `updateParticipation` Allows Excess Tokens and, Disallow Legit Participation Update

Jan '25

Next Generation

Next Generation

3.65 USDC • 1 total finding • Code4rena • Limbooo

#14

high

Cross-Chain Signature Replay Attack Due to User-Supplied `domainSeparator` and Missing Deadline Check

Dec '24

bima-money

bima-money

380.11 USDC • 1 total finding • Cantina • Kasheeda

#20

medium

Finding not yet public.

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

0.38 USDC • 1 total finding • Sherlock • Limbooo

#33

high

Inclusion of fees in `marketFunds` leads to insolvent market operations

Oct '24

Omni Network

Omni Network

392.58 USDC • 1 total finding • Cantina • Kasheeda

#19

medium

Finding not yet public.

Sep '24

Royco Protocol

Royco Protocol

401.99 USDC • 6 total findings • Cantina • Kasheeda

#21

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Flayer

Flayer

8.36 USDC • 1 total finding • Sherlock • Limbooo

#68

high

User is Unable to Reclaim Vote After Collection Shutdown is Canceled

Jun '24

Thorchain

Thorchain

18.87 USDC • 1 total finding • Code4rena • Limbooo

#19

medium

Due to the use of `msg.value` in for loop, anyone can drain all the funds from the `THORChain_Router` contract

May '24

Olas

Olas

302.17 USDC • 1 total finding • Code4rena • Limbooo

#11

medium

Incorrect Handling of Last Nominee Removal in `removeNominee` Function

Munchables

Munchables

28.82 USDC • 3 total findings • Code4rena • Limbooo

#11

high

Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens

high

Invalid validation allows users to unlock early

medium

Players can gain more NFTs benefiting from that past remainder in subsequent locks

Apr '24

Renzo

Renzo

0 USDC • Code4rena • Limbooo

#58

DYAD

DYAD

349.77 USDC • 5 total findings • Code4rena • Limbooo

#32

high

Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine

high

Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply

high

User can get their Kerosene stuck because of an invalid check on withdraw

high

Unable to withdraw Kerosene from `vaultmanagerv2::withdraw` as it expects a `vault.oracle()` method which is missing in Kerosene vaults

high

Attacker Can Frontruns User's Withdrawals To Make Them Reverts Without Costs

Mar '24

Ondo Finance

Ondo Finance

2,980.53 USDC • 2 total findings • Code4rena • Limbooo

#6

medium

Inadequate Handling of BUIDL Redemption Limit in OUSG Instant Manager

medium

The `BURNER` cannot burn tokens from accounts not KYC verified due to the check in `_beforeTokenTransfer`.

Smart Wallet

Smart Wallet

36.34 USDC • Code4rena • Limbooo

#14

Abracadabra Mimswap

Abracadabra Mimswap

2,068.88 USDC • 1 total finding • Code4rena • Limbooo

#6

medium

Pool Creation Failure Due to WETH Transfer Compatibility Issue on Some Chains

Taiko

Taiko

835.1 USDC • 1 total finding • Code4rena • Limbooo

#20

medium

Incorrect __Essential_init() function is used in TaikoToken making snapshooter devoid of calling snapshot()

Revert Lend

Revert Lend

24.06 USDC • 1 total finding • Code4rena • Limbooo

#64

medium

V3Vault is not ERC-4626 compliant

Feb '24

Spectra

Spectra

80.57 USDC • 1 total finding • Code4rena • Limbooo

#17

medium

PrincipalToken is not ERC-5095 compliant

Althea Liquid Infrastructure

Althea Liquid Infrastructure

106.29 USDC • 2 total findings • Code4rena • Limbooo

#22

medium

`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.

medium

Distribution can be bricked, and double claims by a few holders are possible when owner calls `LiquidInfrastructureERC20::setDistributableERC20s`

AI Arena

AI Arena

0.1 USDC • 2 total findings • Code4rena • Limbooo

#183

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

Jan '24

Salty.IO

Salty.IO

8.76 USDC • 1 total finding • Code4rena • Limbooo

#114

medium

Adversary can prevent updating price feed addresses by creating poisonous proposals ending in `_confirm`

Oct '23

Ethena Labs

Ethena Labs

280.94 USDC • 2 total findings • Code4rena • Limbooo

#15

medium

Soft Restricted Staker Role can withdraw stUSDe for USDe

medium

``FULL_RESTRICTED`` Stakers can bypass restriction through approvals

ENS

ENS

16.12 USDC • Code4rena • Limbooo

#17

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

79.32 USDC • 3 total findings • Code4rena • Limbooo

#40

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

medium

Incorrect source address decoding in RootBridgeAgent and BranchBridgeAgent's _requiresEndpoint breaks LayerZero communication

medium

Message channels can be blocked resulting in DoS

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

3.86 USDC • Code4rena • Limbooo

#58

Tangible Caviar

Tangible Caviar

116.74 USDC • Code4rena • Limbooo

#47

Good Entry

Good Entry

625.44 USDC • 1 total finding • Code4rena • Limbooo

#17

high

V3Proxy swapTokensForExactETH does not send back to the caller the unused input tokens

Jul '23

Amphora Protocol

Amphora Protocol

527.07 USDC • Code4rena • Limbooo

#11

Lens Protocol V2

Lens Protocol V2

2,660.6 USDC • 1 total finding • Code4rena • Limbooo

#7

medium

Token guardian protection doesn't account for approved operators in `approve()`

Tapioca DAO

Tapioca DAO

99.24 USDC • 1 total finding • Code4rena • Limbooo

#77

medium

Tapioca Bar: Unusable Market Add Functions in Penrose Contract

Jul '22

Golom contest

Golom contest

93.28 USDC • Code4rena • Limbooo

#76

Yield Witch v2 contest

Yield Witch v2 contest

20.97 USDC • Code4rena • Limbooo

#45

ENS contest

ENS contest

460.94 USDC • 2 total findings • Code4rena • Limbooo

#20

medium

Users can create extra ENS records at no cost

medium

transfer() depends on gas consts

Fractional v2 contest

Fractional v2 contest

38.9 USDC • 1 total finding • Code4rena • Limbooo

#95

medium

Use of `payable.transfer()` may lock user funds

Juicebox V2 contest

Juicebox V2 contest

49.21 USDC • 1 total finding • Code4rena • Limbooo

#57

medium

Use a safe transfer helper library for ERC20 transfers

Jun '22

Putty contest

Putty contest

68.31 USDC • Code4rena • Limbooo

#69

Canto v2 contest

Canto v2 contest

43.14 USDC • Code4rena • Limbooo

#34

Nibbl contest

Nibbl contest

45.5 USDC • Code4rena • Limbooo

#50

Yieldy contest

Yieldy contest

79.73 USDC • Code4rena • Limbooo

#56

Illuminate contest

Illuminate contest

63.94 USDC • Code4rena • Limbooo

#56

Canto contest

Canto contest

304.72 USDC • Code4rena • Limbooo

#37