https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/683c2e25-bd52-4b19-800a-af485b84f01a.jpg

Nadin

Security Researcher

Contact Me

High

3

Total

Medium

14

Total

$9.73K

Total Earnings

#665 All Time

34x

Payouts

bronze

2x

3rd Places

regular

4x

Top 10

regular

14x

Top 25

All

Sherlock

Code4rena

CodeHawks

Aug '23

Sparkn

Sparkn

7.54 USDC • 1 total finding • CodeHawks • nadin

#60

low

Precision loss/Rounding to Zero in `_distribute()`

PoolTogether V5: Part Deux

PoolTogether V5: Part Deux

2,768.02 USDC • 2 total findings • Code4rena • nadin

bronze

medium

PRBMATH `SD59x18.exp()` reverts on hugely negative numbers.

medium

create methods are suspicious of the reorg attack

Good Entry

Good Entry

482.48 USDC • 1 total finding • Code4rena • nadin

#18

high

Incorrect Solidity version in FullMath.sol can cause permanent freezing of assets for arithmetic underflow-induced revert

Jul '23

Moonwell

Moonwell

542.23 USDC • 2 total findings • Code4rena • nadin

#20

medium

missing check for the max/min price in the `chainlinkOracle.sol` contract

medium

accrueInterest is expected to revert when the rate is higher than the maximum allowed rate, which is possible since the utilization can be more than 1

Tokemak

Tokemak

67.15 USDC • 1 total finding • Sherlock • Nadin

#48

medium

`LMPVault.sol` does not match EIP4626 because of `preview` functions.

PoolTogether

PoolTogether

357.36 USDC • 1 total finding • Code4rena • nadin

#37

medium

In important libraries of PoolTogether, the pow() function of PRBMath is used, which exhibits inconsistent return values

Tapioca DAO

Tapioca DAO

182.52 USDC • 1 total finding • Code4rena • nadin

#67

medium

FullMath and TickMath libraries desire overflow behavior

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

88.63 USDC • 1 total finding • Code4rena • nadin

#60

medium

[M-01] Some functions in Talos contracts does not allow user to supply slippage and deadline, which may cause swap revert

Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

788.63 USDC • 1 total finding • Code4rena • nadin

#22

medium

Borrow rate calculation can cause VToken.accrueInterest() to revert, DoSing all major functionality

Mar '23

Asymmetry contest

Asymmetry contest

17.67 USDC • 1 total finding • Code4rena • nadin

#105

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

Jan '23

Popcorn contest

Popcorn contest

94.72 USDC • 2 total findings • Code4rena • nadin

#66

high

First vault depositor can steal other's assets

medium

Malicious Users Can Drain The Assets Of Vault. (Due to not being ERC4626 Complaint)

Numoen contest

Numoen contest

1,874.73 USDC • 1 total finding • Code4rena • nadin

#5

medium

Wrong init code hash

Timeswap contest

Timeswap contest

212.75 USDC • 1 total finding • Code4rena • nadin

#18

medium

Fee on transfer tokens will not behave as expected

Dec '22

GoGoPool contest

GoGoPool contest

57.2 USDC • 1 total finding • Code4rena • nadin

#68

medium

Users may not be able to redeem their shares due to underflow

Oct '22

Holograph contest

Holograph contest

1.97 USDC • 1 total finding • Code4rena • nadin

#42

medium

Bad source of randomness