https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/e4a5d01c-286f-41b0-bc97-f302aaaf0ee5.jpg

ParthMandale

Security Researcher

I find bugs🛡️

Contact Me

High

9

Total

Medium

9

Total

$4.40K

Total Earnings

#833 All Time

8x

Payouts

gold

1x

1st Places

regular

2x

Top 10

regular

4x

Top 25

All

Sherlock

Code4rena

Cantina

Jan '25

Aave v3.3

Aave v3.3

87.40 USDC • Sherlock • ParthMandale

#85

Dec '24

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

106.08 OP • 12 total findings • Sherlock • ParthMandale

#21

high

In reality borrowers will not receive Downside Protection in `BorrowLib::withdraw`

high

Strike Price Not Validated Against Strike Percent, Leading to Exploitation Risk

high

`CDS::redeemUSDT` is vulnerable to input price manipulation attack, leading attacker to drain USDT from treasury.

high

DoS in core functionality of the CDS contract due to `CDS::updateDownsideProtected` getting set to arbitrarily large value by a malicious user.

high

Incorrect check in `BorrowLib::getOptionFeesToPay` will never revert the `renewOptions` flow for borrowers, causing a negative impact on the protocol.

high

Borrowers will enjoy the downside protection in `borrowing::withDraw` even after their position's options maturity expires.

high

User will not recive any USDa token in `borrowing::redeemYields`

medium

Liquidation type 1 is prone to underflow Revert DoS.

medium

Underflow revert in `liquidationType1` due to `borrowerDebt` amount being more than the amount of collateral asset deposited.

medium

`Borrowing::_withdraw` updating `lastEventTime` even before calling `calculateCumulativeRate()` which will lead to incorrect calculations and update `lastCumulativeRate`

medium

DoS in Liquidation type 2

medium

Inflated Position Sizing Due to Miscalculation in `sizeDelta` Parameter in `BorrowingLiquidation::liquidationType2`

Sep '24

Boost Core Incentive Protocol

Boost Core Incentive Protocol

9.11 USDC • 1 total finding • Sherlock • ParthMandale

#23

medium

Denial of service for `ManagedBudged::allocate` when asset token type is `AssetType.ERC20` "Fee on Transfer" token.

Aug '24

zetachain-protocol

zetachain-protocol

107.55 USDC • 3 total findings • Cantina • ParthMandale

#60

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

MakerDAO Endgame

MakerDAO Endgame

516.45 USDC • Sherlock • ParthMandale

#71

Jun '24

Size

Size

0.05 USDC • 1 total finding • Code4rena • ParthMandale

#62

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

May '24

LoopFi

LoopFi

0 USDC • Code4rena • ParthMandale

#10

Mar '24

Mento

Mento

3,571.42 USDC • 1 total finding • Sherlock • ParthMandale

gold

medium

`Locking::withdraw` & `Locking::getAvailableForWithdraw` , Users can withdraw their entire locked MENTO token and still retain veMENTO tokens, which they can use to cast votes.