https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_1.png

NentoR

Security Researcher

Contact Me

High

10

Total

Medium

10

Total

$9.60K

Total Earnings

#567 All Time

8x

Payouts

regular

2x

Top 10

regular

4x

Top 25

regular

4x

Top 50

All

Code4rena

CodeHawks

Apr '24

Renzo

Renzo

529.4 USDC • 5 total findings • Code4rena • NentoR

#21

high

Incorrect withdraw queue balance in TVL calculation

high

Incorrect calculation of queued withdrawals can deflate TVL and increase ezETH mint rate

medium

Lack of slippage and deadline during withdraw and deposit

medium

Fixed hearbeat used for price validation is too stale for some tokens

medium

Withdrawals and Claims are meant to be pausable, but it is not possible in practice

DYAD

DYAD

204.68 USDC • 3 total findings • Code4rena • NentoR

#56

high

Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral

high

Inability to perform partial liquidations allows huge positions to accrue bad debt in the system

high

Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply

Feb '24

Wise Lending

Wise Lending

8,036.28 USDC • 2 total findings • Code4rena • NentoR

#6

medium

`PendlePowerFarmToken:: totalLpAssetsToDistribute` may lead to temporary DOS due to price growth check being skipped during deposit

medium

`PendlePowerManager` is incompatible with `PendleRouterV3`

Jan '24

Decent

Decent

415.31 USDC • 4 total findings • Code4rena • NentoR

#19

high

Due to missing checks on minimum gas passed through LayerZero, executions can fail on the destination chain

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

medium

Potential loss of capital due to fixed fee calculations

medium

Missing access control on UTB:receiveFromBridge allows UTB swaps to be executed without spending bridge fees while bypassing fee/swap instruction signature verification

reNFT

reNFT

14.38 USDC • Code4rena • NentoR

#58

Dec '23

The Standard

The Standard

332.81 USDC • 4 total findings • CodeHawks • NentoR

#10

high

Rewards can be drained because of lack of access control

high

Looping over unbounded `pendingStakes` array can lead to permanent DoS and frozen funds

medium

Fees are hardcoded to 3000 in ExactInputSingleParams

medium

Attacker can force reduce `minAmountOut` from vault swaps, making they vulnerable to being sandwiched.

Ethereum Credit Guild

Ethereum Credit Guild

59.6 USDC • 1 total finding • Code4rena • NentoR

#74

medium

Wrong ProfitManager in GuildToken, will always revert for other types of gauges leading to bad debt

Oct '23

NextGen

NextGen

2.77 USDC • 1 total finding • Code4rena • NentoR

#102

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders