Security Researcher
Into the storm
High
Total
Medium
Total Earnings
#626 All Time
Payouts
1st Places
3rd Places
Top 10
All
Sherlock
Code4rena
Jan '25
173.50 USDC • 1 total finding • Sherlock • PNS
#23
medium
Flash minter will create accounting inconsistencies in internal supply tracking
495.92 USDC • 1 total finding • Sherlock • PNS
#20
The false assumption that 1USDC equals 1USD may result in losses to the user or the protocol
Dec '24
0.48 OP • 2 total findings • Sherlock • PNS
#60
high
Duplicate orders in the same block will overwrite previous orders and lead to token loss for the recipient
Lack of validation in `modifyOrder` allows double refunds, draining protocol funds
31.64 OP • 1 total finding • Sherlock • PNS
#37
Token holder can repeatedly spend ABOND tokens due to incorrect state updates in transferFrom
Nov '24
417.50 USDC • Sherlock • PNS
#13
94.59 USDC • 1 total finding • Sherlock • PNS
Attacker will front-run and claim tokens intended for a KYC-verified user
Oct '24
3,351.23 USDC • 3 total findings • Sherlock • PNS
Corruptible Upgradability Pattern
A compromised address does not lose any ability to perform actions on behalf of the profile
Re-registering an address does not remove it from the compromised list
445.40 OP • 2 total findings • Sherlock • PNS
User may lose some rewards due to incorrect accounting
Invariant not met, not all funds will be used for distribution
323.43 USDC • 1 total finding • Sherlock • PNS
#8
Incompatibility of required integration with Aerodrome/Velodrome
Aug '24
178.10 USDC • Sherlock • PNS
#7
7.19 USDC • 2 total findings • Sherlock • PNS
#28
A malicious user can permanently lock the prizes, exposing the protocol to loss
Attacker can block admin from creating a raffle, potentially disrupting the protocol
Jul '24
0.01 USDC • 1 total finding • Code4rena • PNS
#88
Discrepancy between nfts minted, price of nft when a generation changes & position of `_incrementGeneration()` inside `_mintInternal()` & `_mintNewEntity()`
2.35 USDC • 2 total findings • Sherlock • PNS
#59
`Voter.vote` Never succeeds if a bribe is set for the period
`MLumStaking.addToPosition` Has Incorrect Access Control Checks
May '24
726.63 USDC • 2 total findings • Sherlock • PNS
User Can Self-Revoke Role
Contract Upgrade Pattern may be broken
271.03 USDC • 4 total findings • Sherlock • PNS
#19
Lack of Permissions in `AccountFacet.batchUpdateAccountToken()`
Improper Implementation of ReentrancyGuard
Loss Calculation Bug in Request Execution
Improper Removal of Roles in `RoleAccessControlFacet.revokeAllRole()`
189.78 USDC • 2 total findings • Sherlock • PNS
#12
`PufETHAdapter` use wrong deposit function signature from outdated depositor interface
Incorrect staking limit check in `RsETHAdapter`
Apr '24
1.48 USDC • 1 total finding • Code4rena • PNS
#54
Lack of slippage and deadline during withdraw and deposit
Feb '24
240.50 USDC • 1 total finding • Sherlock • PNS
#22
Price arbitrage between different assets supporting a single LRT token
Dec '23
1.34 USDC • 1 total finding • Code4rena • PNS
#75
Bidder can use donations to get VerbsToken from auction that already ended.
Nov '23
292.32 USDC • Code4rena • PNS
#17
Aug '23
0.75 USDC • Code4rena • PNS
#85
Jul '23
9.43 USDC • Code4rena • PNS
Jun '23
21.14 USDC • 1 total finding • Sherlock • PNS
#31
Missing checks for whether arbitrum, optimism or polygon Sequencer is active
May '23
4.59 USDC • 3 total findings • Sherlock • PNS
#73
Incorrect assumptions and calculations about the price of dai/eth
Wrong oracle address WETH/DAI uniswap v3
Lack of checking whether the calculations are based on fresh data from chainlink.
56.63 USDC • Code4rena • PNS
#42
Apr '23
0.07 USDC • 1 total finding • Code4rena • PNS
#69
function `restructureCapTable()` in Equity.sol not functioning as expected
Mar '23
13.13 USDC • Code4rena • PNS
#110