Security Researcher
Solo Smart Contract Auditor | Solidity | Rust | CosmWasm | Substrate | NEAR | EVM
High
Total
Medium
Total Earnings
#2100 All Time
Payouts
All
Code4rena
Feb '24
1.92 USDC • 2 total findings • Code4rena • Matue
#160
medium
Can mint NFT with the desired attributes by reverting transaction
Fighter created by mintFromMergingPool can have arbitrary weight and element
Jan '24
17.42 USDC • 2 total findings • Code4rena • Matue
#52
high
Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.
Missing access control on UTB:receiveFromBridge allows UTB swaps to be executed without spending bridge fees while bypassing fee/swap instruction signature verification
31.2 USDC • 1 total finding • Code4rena • Matue
#100
Reusing a SALT that has already been used for voting can allow a malicious proposal to pass and compromise the protocol.
2.19 USDC • 3 total findings • Code4rena • Matue
#118
Attack to make ````CurveSubject```` to be a ````HoneyPot````
Unauthorized Access to setCurves Function
If a user sets their curve token symbol as the default one plus the next token counter instance it will render the whole default naming functionality obsolete