https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/b40bf5f1-dd77-4395-b1f0-5242d70b3592.jpg

Lirios

Security Researcher

Blockchain security researcher, Interests include Ai, Defi, Security, Cryptography, NFT, Blockchain research

Contact Me

High

11

Total

Medium

4

Total

$12.73K

Total Earnings

#502 All Time

13x

Payouts

regular

2x

Top 10

regular

4x

Top 25

regular

6x

Top 50

All

Code4rena

Jan '24

Curves

Curves

0 USDC • 1 total finding • Code4rena • Lirios

#137

high

Unauthorized Access to setCurves Function

reNFT

reNFT

88.09 USDC • Code4rena • Lirios

#40

Jun '23

Canto

Canto

3,388.28 USDC • 1 total finding • Code4rena • Lirios

#4

high

Pre-defined limit is different from the spec.

May '23

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

3,544.41 USDC • Code4rena • Lirios

#16

Apr '23

Frankencoin

Frankencoin

79.41 USDC • 2 total findings • Code4rena • Lirios

#51

high

CHALLENGER_REWARD can be used to drain reserves and free mint

medium

Can't pause or remove a minter

Rubicon v2

Rubicon v2

105.82 USDC • 2 total findings • Code4rena • Lirios

#55

high

RubiconMarket batchOffer and batchRequote make offers as self; complete loss of funds for some types of tokens, for example WETH

high

Reward accounting is incorrect in BathBuddy contract

Mar '23

Asymmetry contest

Asymmetry contest

8.41 USDC • 2 total findings • Code4rena • Lirios

#118

high

Staking, unstaking and rebalanceToWeight can be sandwiched (Mainly rETH deposit )

medium

DoS due to external call failure

Polynomial Protocol contest

Polynomial Protocol contest

5,034.85 USDC • Code4rena • Lirios

#4

Neo Tokyo contest

Neo Tokyo contest

154.74 USDC • 1 total finding • Code4rena • Lirios

#18

high

Underflow of `lpPosition.points` during withdrawLP causes huge reward minting

Jan '23

Popcorn contest

Popcorn contest

185.24 USDC • 2 total findings • Code4rena • Lirios

#56

medium

vault.changeAdapter can be misused to drain fees

medium

Anyone can reset fees to 0 value when Vault is deployed

Astaria contest

Astaria contest

43.21 USDC • 1 total finding • Code4rena • Lirios

#54

high

Improper validations in Clearinghouse. possible to lock collateral NFT in contract.

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

85.48 USDC • 2 total findings • Code4rena • Lirios

#47

high

Arbitrary transactions possible due to insufficient signature validation

high

Attacker can gain control of counterfactual wallet

Dec '22

GoGoPool contest

GoGoPool contest

9.93 USDC • 1 total finding • Code4rena • Lirios

#80

high

Hijacking of node operators minipool causes loss of staked funds