https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

Musaka

Security Researcher

Contact Me

High

4

Total

Medium

7

Total

$2.89K

Total Earnings

#965 All Time

4x

Payouts

regular

3x

Top 10

regular

4x

Top 25

regular

4x

Top 50

All

Sherlock

Code4rena

Jul '23

Amphora Protocol

Amphora Protocol

732.43 USDC • 1 total finding • Code4rena • Musaka

#10

high

Rounding error in `WUSDA` can result in loss of user funds, especially when manipulated by an attacker

Tokensoft

Tokensoft

239.82 USDC • 2 total findings • Sherlock • Musaka

#10

high

`setMerkleRoot` is wrongly implemented and if used it will break the contract

medium

`_setTotal` will not work

Bond Options

Bond Options

99.50 USDC • 1 total finding • Sherlock • Musaka

#17

high

Users can steal all claimed, but not exercised reward token

Jun '23

Lybra Finance

Lybra Finance

1,819.65 USDC • 7 total findings • Code4rena • Musaka

#6

high

Incorrectly implemented modifiers in LybraConfigurator.sol allow any address to call functions that are supposed to be restricted

medium

Volatile prices and lack of checks on `rigidRedemption()` can cause users to purchase stETH at unwanted prices

medium

If `ProtocolRewardsPool` is insufficient in EUSD, users will not be able to calim any rewards

medium

Due to inappropriately short `votingPeriod` and `votingDelay`, it is near impossible for the governance to function correctly.

medium

Incorrect function call in LybraRETHVault's getAssetPrice

medium

It is possible to manipulate WETH/LBR pair to claim reward of the users which shouldn't be claimed

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called