https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/c95a9a9e-ebc4-4f20-b1db-ca88e4efcc47.png

MrMorningstar

Security Researcher

Contact Me

High

8

Total

Medium

8

Total

$6.75K

Total Earnings

#708 All Time

14x

Payouts

bronze

1x

3rd Places

regular

5x

Top 10

regular

9x

Top 25

All

Code4rena

Cantina

CodeHawks

Immunefi

Apr '25

Audit Comp | Spectra Finance

Audit Comp | Spectra Finance

785 USDC • 3 total findings • Immunefi • MrMorningstar

bronze

medium

Finding not yet public.

low

Finding not yet public.

low

Finding not yet public.

Mar '25

badger-ebtc-bsm

badger-ebtc-bsm

755.04 USDC • 2 total findings • Cantina • mrMorningstar

#7

high

Finding not yet public.

medium

Finding not yet public.

Feb '25

Liquidity Management

Liquidity Management

621.10 usdc • 4 total findings • CodeHawks • mrmorningstar

#12

high

Deposits on long one leverage vault don't actually finalize the flow, leading to a Denial of Service (DoS)

high

Loss of fee refund due to premature state deletion in `PerpetualVault::_handleReturn` function

high

If users withdraw while a position is in loss, the whole PNL of the position to their withdrawal amount instead of just their share of it.

low

Incorrect Token Price Validation in KeeperProxy

Jan '25

daao-contracts

daao-contracts

0.23 USDC • 1 total finding • Cantina • mrMorningstar

#122

medium

Finding not yet public.

reserve-index-dtf

reserve-index-dtf

53.43 USDC • 1 total finding • Cantina • mrMorningstar

#8

medium

Finding not yet public.

Dec '24

Audit Comp | Lombard

Audit Comp | Lombard

2,775 USDC • 2 total findings • Immunefi • MrMorningstar

#5

medium

Finding not yet public.

low

Finding not yet public.

Alchemix Transmuter

Alchemix Transmuter

11.67 op • 1 total finding • CodeHawks • mrmorningstar

#27

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

SecondSwap

SecondSwap

0.83 USDC • 1 total finding • Code4rena • mrMorningstar

#63

medium

Listing potential can not be purchased with discounted price

Lambo.win

Lambo.win

299.22 USDC • 1 total finding • Code4rena • mrMorningstar

#12

medium

Users can prevent protocol from rebalancing for his gain and cause loss of funds for protocol and its users

Oct '24

Audit Comp | Anvil

Audit Comp | Anvil

417 USDT • 1 total finding • Immunefi • MrMorningstar

#7

low

Finding not yet public.

Sep '24

Royco Protocol

Royco Protocol

0.16 USDC • 1 total finding • Cantina • mrMorningstar

#75

high

Finding not yet public.

Jul '24

LoopFi

LoopFi

962.39 USDC • 2 total findings • Code4rena • mrMorningstar

#18

high

Liquidation doesn't account for penalty when calculating collateral to give, allowing users to profit by borrowing and self-liquidating

high

`AuraVault::claim` reward calculation does not deduct fees from reward amount, causing DoS or extra rewards lost

Apr '24

NOYA

NOYA

35.86 USDC + NOYA stars • 1 total finding • Code4rena • mrMorningstar

#68

high

In Dolomite, when opening a borrow position, the holding position in the Registry will never be updated due to the removePosition flag being set to true

Beanstalk Part 2

Beanstalk Part 2

35.74 USDC • 1 total finding • CodeHawks • mrmorningstar

#11

low

Missing the `lookback` parameter when invoking the `getWstethUsdPrice()` in the `getTokenPrice` function