Security Researcher
coping at reading codes
High
Total
Medium
Total Earnings
#662 All Time
Payouts
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
CodeHawks
Oct '24
1,335.75 USDC • CodeHawks • 0xokomo
#23
392.58 USDC • 1 total finding • Cantina • OKOMO
medium
Sep '24
70.19 USDC • CodeHawks • 0xokomo
#32
Aug '24
178.86 USDC • 3 total findings • Code4rena • OMEN
high
Missing `lower<upper` check in `mint_position`
If liquidity is insufficient, users may need to pay more tokens in swap2
_onTransferReceived() does not work as intended
324.32 USDC • 1 total finding • Cantina • OKOMO
#43
Jul '24
360.6 USDC • 1 total finding • Code4rena • OMEN
#12
Lack of Slippage Protection in Dynamic Pricing Mint Function
2,359.11 OP • 1 total finding • Code4rena • OMEN
#13
The `MIPS` doesn't implement `ADD`, `ADDI`, and `SUB` instructions correctly
92.18 USDC • Sherlock • OMEN
#100
Apr '24
18.61 USDC • 3 total findings • Code4rena • OMEN
#39
Incorrect withdraw queue balance in TVL calculation
Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps
Pending withdrawals prevent safe removal of collateral assets
72.37 USDC • 1 total finding • Sherlock • OMEN
#26
iq 200 user will exploit the interest amount distribution and avoid loss from liquidation
223 USDC • 3 total findings • Code4rena • OMEN
#53
Inability to perform partial liquidations allows huge positions to accrue bad debt in the system
No incentive to liquidate small positions could result in protocol going underwater
No incentive to liquidate when CR <= 1 as asset received < dyad burned
Feb '24
1.27 USDC • 1 total finding • Code4rena • OMEN
#166
Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes
Jan '24
405.39 USDC • 3 total findings • Code4rena • OMEN
#33
The use of spot price by CoreSaltyFeed can lead to price manipulation and undesired liquidations
First Liquidity provider can claim all initial pool rewards
Chainlink price feed uses BTC, not WBTC. In case of depegging, oracles will become easier to manipulate.
1.08 USDC • 1 total finding • Code4rena • OMEN
#129
Attack to make ````CurveSubject```` to be a ````HoneyPot````
45.31 USDC • Code4rena • OMEN
#46
Dec '23
299.13 USDC • 1 total finding • Code4rena • OMEN
#42
Auction manipulation by block stuffing and reverting on ERC-777 hooks
Nov '23
4.08 USDC • Code4rena • OMEN
#30
Oct '23
117.51 USDC • Code4rena • OMEN
#15
Sep '23
46.91 USDC • 1 total finding • Code4rena • OMEN
#48
If RootBridgeAgent.lzReceiveNonBlocking reverts internally, the native token sent by relayer to RootBridgeAgent is left in RootBridgeAgent
Jun '23
5.53 USDC • 1 total finding • Code4rena • OMEN
#84
Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called