https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

OMEN

Security Researcher

coping at reading codes

Contact Me

High

10

Total

Medium

13

Total

$14.40K

Total Earnings

#442 All Time

21x

Payouts

bronze

1x

3rd Places

regular

1x

Top 10

regular

7x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Jan '25

Initia Rollup Modules

Initia Rollup Modules

8,050 USDC • 1 total finding • Code4rena • OMEN

bronze

high

Storage Root Assignment Missing in Tree Finalization

Oct '24

Era

Era

1,335.75 USDC • CodeHawks • 0xokomo

#23

Omni Network

Omni Network

392.58 USDC • 1 total finding • Cantina • OKOMO

#19

medium

Finding not yet public.

Sep '24

Staking

Staking

70.19 USDC • CodeHawks • 0xokomo

#32

Aug '24

Superposition

Superposition

178.86 USDC • 3 total findings • Code4rena • OMEN

#23

high

Missing `lower<upper` check in `mint_position`

medium

If liquidity is insufficient, users may need to pay more tokens in swap2

medium

_onTransferReceived() does not work as intended

zetachain-protocol

zetachain-protocol

324.32 USDC • 1 total finding • Cantina • OKOMO

#36

medium

Finding not yet public.

Jul '24

TraitForge

TraitForge

360.6 USDC • 1 total finding • Code4rena • OMEN

#12

medium

Lack of Slippage Protection in Dynamic Pricing Mint Function

Optimism Superchain

Optimism Superchain

2,359.11 OP • 1 total finding • Code4rena • OMEN

#13

medium

The `MIPS` doesn't implement `ADD`, `ADDI`, and `SUB` instructions correctly

MakerDAO Endgame

MakerDAO Endgame

92.18 USDC • Sherlock • OMEN

#100

Apr '24

Renzo

Renzo

18.61 USDC • 3 total findings • Code4rena • OMEN

#39

high

Incorrect withdraw queue balance in TVL calculation

high

Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps

medium

Pending withdrawals prevent safe removal of collateral assets

Teller Finance

Teller Finance

72.37 USDC • 1 total finding • Sherlock • OMEN

#26

high

iq 200 user will exploit the interest amount distribution and avoid loss from liquidation

DYAD

DYAD

223 USDC • 3 total findings • Code4rena • OMEN

#53

high

Inability to perform partial liquidations allows huge positions to accrue bad debt in the system

medium

No incentive to liquidate small positions could result in protocol going underwater

medium

No incentive to liquidate when CR <= 1 as asset received < dyad burned

Feb '24

AI Arena

AI Arena

1.27 USDC • 1 total finding • Code4rena • OMEN

#166

high

Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes

Jan '24

Salty.IO

Salty.IO

405.39 USDC • 3 total findings • Code4rena • OMEN

#33

high

The use of spot price by CoreSaltyFeed can lead to price manipulation and undesired liquidations

high

First Liquidity provider can claim all initial pool rewards

medium

Chainlink price feed uses BTC, not WBTC. In case of depegging, oracles will become easier to manipulate.

Curves

Curves

1.08 USDC • 1 total finding • Code4rena • OMEN

#129

high

Attack to make ````CurveSubject```` to be a ````HoneyPot````

reNFT

reNFT

45.31 USDC • Code4rena • OMEN

#46

Dec '23

Ethereum Credit Guild

Ethereum Credit Guild

299.13 USDC • 1 total finding • Code4rena • OMEN

#42

medium

Auction manipulation by block stuffing and reverting on ERC-777 hooks

Nov '23

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

4.08 USDC • Code4rena • OMEN

#30

Oct '23

Badger eBTC Audit + Certora Formal Verification Competition

Badger eBTC Audit + Certora Formal Verification Competition

117.51 USDC • Code4rena • OMEN

#15

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

46.91 USDC • 1 total finding • Code4rena • OMEN

#48

medium

If RootBridgeAgent.lzReceiveNonBlocking reverts internally, the native token sent by relayer to RootBridgeAgent is left in RootBridgeAgent

Jun '23

Lybra Finance

Lybra Finance

5.53 USDC • 1 total finding • Code4rena • OMEN

#84

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called