https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/3d6aea3f-38c9-402e-a73e-9621ccdefd0b.jpg

Pablo

Security Researcher

Contact Me

High

10

Total

Medium

9

Total

$683.00

Total Earnings

#1343 All Time

9x

Payouts

regular

3x

Top 10

regular

4x

Top 25

regular

8x

Top 50

All

Sherlock

Code4rena

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

458.74 USDC • 1 total finding • Code4rena • PabloPerez

#13

high

Early 72-digit adjustment in sqrt will lead to incorrect result exponent calculation

Symmio, Staking and Vesting

Symmio, Staking and Vesting

68.35 USDC • 2 total findings • Sherlock • Pablo

#10

high

The rewards distribution system in SymmStaking could be disturbed due to missing precision factor.

medium

The rewards distribution system in SymmStaking can be diluted by extending the state.periodFinish

Feb '25

THORWallet

THORWallet

0 USDC • 1 total finding • Code4rena • PabloPerez

#10

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Jan '25

Liquid Ron

Liquid Ron

0.03 USDC • 1 total finding • Code4rena • PabloPerez

#10

high

The calculation of `totalAssets()` could be wrong if `operatorFeeAmount` > 0, this can cause potential loss for the new depositors

Plaza Finance

Plaza Finance

84.01 USDC • 6 total findings • Sherlock • Pablo

#38

high

User can claim coupon without participating for protocol activity, due to missing minimum duration between `create()` and `redeem()`

high

`Pool.transferReserveToAuction()` uses incorrect index for current auction

high

The proctol claims incorrect amount of fees in pool and this is unfair to users

medium

The funds of the user can be lost while accessing with `joinBalancerAndPredeposit()`

medium

`Pool.startAuction()` updates state variable `BondToken.globalPool` incorrectly

medium

The mixing of updating `globalPool.previousPoolAmounts` and `globalPool.sharesPerToken` could increase the coupon tokens that bond holders can claim.

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

0.47 OP • 1 total finding • Sherlock • Pablo

#61

high

The funds of the protocol can be drained due to incorrect handling of cancel order.

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

46.19 OP • 5 total findings • Sherlock • Pablo

#33

high

The user overpays the USDA amount for downside protection while withdrawing

high

The user can withdraw more collateral due to uncheck for `strikePrice`

medium

Incorrect calculation for borrowing fees

medium

The invariants of protocol could be broken due to not updating `lastEthprice` while depositing

medium

The `CDS.withdraw` will be DOS when current `exchangeRate` is fewer than liquidation exchangeRate

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

0.38 USDC • 1 total finding • Sherlock • Pablo

#33

high

The funds of the ReputationMarket contract can be drained due to incorrect accounting of fees.

Debita Finance V3

Debita Finance V3

25.05 USDC • 1 total finding • Sherlock • Pablo

#42

medium

User can seize most incentives without participating in activity for protocol.