https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

RaymondFam

Security Researcher

Contact Me

High

13

Total

Medium

2

Solo

43

Total

$43.77K

Total Earnings

#200 All Time

67x

Payouts

silver

1x

2nd Places

bronze

1x

3rd Places

regular

19x

Top 10

All

Sherlock

Code4rena

Jun '23

Stader Labs

Stader Labs

0 USDC • 1 total finding • Code4rena • RaymondFam

#37

medium

no bidder has incentive to bid the Auction except doing last-minute MEV due to fixed endBlock

May '23

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

59.42 USDC • Code4rena • RaymondFam

#43

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

63.74 USDC • 5 total findings • Sherlock • RaymondFam

#33

high

Access control vulnerabilities on USSD.mintRebalancer() and USSD.burnRebalancer()

high

Lack of safeguards in USSD.UniV3SwapInput()

medium

Chainlink price feed is not sufficiently validated and can return stale price

medium

StableOracleWBTC's Dependency on BTC/USD Chainlink Oracle: Risk of Mispricing WBTC in Event of Depegging

medium

Risk of Incorrect Asset Pricing by StableOracle in Case of Underlying Aggregator Reaching minAnswer

Juicebox Buyback Delegate

Juicebox Buyback Delegate

2,258.34 USDC • Code4rena • RaymondFam

silver
Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

108.31 USDC • 1 total finding • Code4rena • RaymondFam

#38

medium

Exchange Rate can be manipulated

Apr '23

EigenLayer Contest

EigenLayer Contest

2,566.01 USDC • 1 total finding • Code4rena • RaymondFam

#6

medium

A staker with verified over-commitment can potentially bypass slashing completely

JOJO Exchange

JOJO Exchange

624.63 USDC • 1 total finding • Sherlock • RaymondFam

#20

medium

Later borrowers will pay less interest compared to earlier borrowers over the same period

ENS Contest

ENS Contest

59.79 USDC • Code4rena • RaymondFam

#20

Teller

Teller

1,231.77 USDC • 2 total findings • Sherlock • RaymondFam

#5

medium

repayLoanMinimum() and repayLoan() do not check if loan has been defaulted and collaterals claimed by the lender

medium

EMI last payment not handled perfectly could lead to borrower losing collaterals

Frankencoin

Frankencoin

772.74 USDC • 2 total findings • Code4rena • RaymondFam

#14

medium

Later challengers can bid on the previous challenge to extend the expiration time of the previous challenge, so that their own challenge can succeed before the previous challenge and get challenge rewards

medium

POSITION LIMIT COULD BE FULLY REDUCED TO ZERO BY CLONES

Caviar Private Pools

Caviar Private Pools

121 USDC • 3 total findings • Code4rena • RaymondFam

#37

medium

Incorrect protocol fee is taken when changing NFTs

medium

Royalty recipients will not get fair share of royalties

medium

Flash loan fee is incorrect in Private Pool contract

Rubicon v2

Rubicon v2

41.66 USDC • 3 total findings • Code4rena • RaymondFam

#83

medium

Incorrect fee handling in Position.sol's Market Buy/Sell functions

medium

Incorrect calculations can occur when calling `Position._marketBuy` and `Position._marketSell` functions that do not include maker fee in `_fee`

medium

Calling `Position._marketBuy` and `Position._marketSell` functions that calculate `_fee` by dividing by `10000` can cause incorrect calculations

Mar '23

Gitcoin

Gitcoin

119.85 USDC • Sherlock • RaymondFam

#28

Asymmetry contest

Asymmetry contest

210.37 USDC • 3 total findings • Code4rena • RaymondFam

#30

high

An attacker can manipulate the preDepositvePrice to steal from other users.

medium

No slippage protection on `stake()` in SafEth.sol

medium

Residual ETH unreachable and unuitilized in SafEth.sol

Olympus Update

Olympus Update

472.63 USDC • 1 total finding • Sherlock • RaymondFam

bronze

medium

Normal users could be inadvertently grieved by the withdrawn ratios check

Polynomial Protocol contest

Polynomial Protocol contest

4,602.3 USDC • Code4rena • RaymondFam

#5

Neo Tokyo contest

Neo Tokyo contest

203.71 USDC • 1 total finding • Code4rena • RaymondFam

#13

high

Underflow of `lpPosition.points` during withdrawLP causes huge reward minting

Wenwin contest

Wenwin contest

12.72 USDC • Code4rena • RaymondFam

#27

Taurus

Taurus

183.09 USDC • 1 total finding • Sherlock • RaymondFam

#10

high

Use of hard coded decimals of 18 for collateral token

Aragon Protocol contest

Aragon Protocol contest

126.39 USDC • Code4rena • RaymondFam

#13

Feb '23

Surge

Surge

10.60 USDC • 2 total findings • Sherlock • RaymondFam

#20

high

First deposit can be exploited to break share calculation

medium

Front-runnable `approve()`

OlympusDAO

OlympusDAO

917.43 USDC • 2 total findings • Sherlock • RaymondFam

#8

high

Users choosing not to claim rewards when withdrawing LP tokens could reap higher rewards later

medium

`_accumulateExternalRewards()` could turn into an infinite loop if the check condition is true

Ethos Reserve contest

Ethos Reserve contest

103.33 USDC • Code4rena • RaymondFam

#32

OpenQ

OpenQ

22.25 USDC • 1 total finding • Sherlock • RaymondFam

#45

medium

Double-entry point (Two Address) token might raise some issues

Jan '23

Popcorn contest

Popcorn contest

54.34 USDC • 2 total findings • Code4rena • RaymondFam

#74

high

First vault depositor can steal other's assets

medium

Fee on transfer token not supported

Numoen contest

Numoen contest

738.88 USDC • 1 total finding • Code4rena • RaymondFam

#12

medium

Fee on transfer tokens will not behave as expected

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

40.28 USDC • 2 total findings • Code4rena • RaymondFam

#55

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts

medium

Users may not claim Erc1155 rewards when the Quest has ended

Timeswap contest

Timeswap contest

1,760.69 USDC • 1 total finding • Code4rena • RaymondFam

#9

medium

Fee on transfer tokens will not behave as expected

OpenSea Seaport 1.2 contest

OpenSea Seaport 1.2 contest

1,347.17 USDC • Code4rena • RaymondFam

#6

Ondo Finance contest

Ondo Finance contest

735.46 USDC • Code4rena • RaymondFam

#9

Reserve contest

Reserve contest

1,077.08 USDC • Code4rena • RaymondFam

#19

Astaria contest

Astaria contest

641.83 USDC • 1 total finding • Code4rena • RaymondFam

#23

medium

Lack of support for fee-on-transfer token

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

75.26 USDC • Code4rena • RaymondFam

#50

Dec '22

Papr contest

Papr contest

748.3 USDC • Code4rena • RaymondFam

#13

GoGoPool contest

GoGoPool contest

2,445.14 USDC • 5 total findings • Code4rena • RaymondFam

#5

high

node operator is getting slashed for full duration even though rewards are distributed based on a 14 day cycle

high

ProtocolDAO lacks a method to take out GGP

medium

MultisigManager may not be able to add a valid Multisig

medium

State Transition: Minipools can be created using other operator's AVAX deposit via recreateMinipool

medium

Bypass `whenNotPaused` modifier

Forgeries contest

Forgeries contest

71.66 USDC • Code4rena • RaymondFam

#19

Caviar contest

Caviar contest

105.25 USDC • 1 total finding • Code4rena • RaymondFam

#32

high

Liquidity providers may lose funds when adding liquidity

prePO contest

prePO contest

721.74 USDC • Code4rena • RaymondFam

#12

Escher contest

Escher contest

1,805.27 USDC • 2 total findings • Code4rena • RaymondFam

#5

medium

`buy()` in `LPDA.sol` Can be Manipulated by Buyers

medium

Use of `payable.transfer()` Might Render ETH Impossible to Withdraw

Maverick contest

Maverick contest

119.07 USDC • Code4rena • RaymondFam

#12

Nov '22

ParaSpace contest

ParaSpace contest

4,083.64 USDC • 4 total findings • Code4rena • RaymondFam

#8

high

Data corruption in NFTFloorOracle; Denial of Service

medium

Semi-erroneous Median Value

medium

During oracle outages or feeder outages/disagreement, the `ParaSpaceFallbackOracle` is not used

medium

Centralization risk: admin can with rug the project by removing asset and price manipulation on oracle.

Canto contest

Canto contest

73.58 CANTO • Code4rena • RaymondFam

#10

Redacted Cartel contest

Redacted Cartel contest

771.68 USDC • Code4rena • RaymondFam

#18

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

58.28 USDC • 1 total finding • Code4rena • RaymondFam

#51

medium

Calling `updateNodeRunnerWhitelistStatus` function always reverts

Blur Exchange contest

Blur Exchange contest

64.77 USDC • 1 total finding • Code4rena • RaymondFam

#27

medium

Protocol can be easily rug-pulled by the owner

LooksRare Aggregator contest

LooksRare Aggregator contest

429.24 USDC • Code4rena • RaymondFam

#8

SIZE contest

SIZE contest

1,076.82 USDC • 2 total findings • Code4rena • RaymondFam

#5

medium

Attacker may DOS auctions using invalid bid parameters

medium

Incompatibility with fee-on-transfer/inflationary/deflationary/rebasing tokens, on both base tokens and quote tokens, with varying impacts

Debt DAO contest

Debt DAO contest

115.92 USDC • 1 total finding • Code4rena • RaymondFam

#40

medium

address.call{value:x}() should be used instead of payable.transfer()

Chainlink Staking contest

Chainlink Staking contest

2,016.66 USDC • Code4rena • RaymondFam

#11

Oct '22

Paladin - Warden Pledges contest

Paladin - Warden Pledges contest

304.48 USDC • Code4rena • RaymondFam

#18

Inverse Finance contest

Inverse Finance contest

417.83 USDC • Code4rena • RaymondFam

#23

Holograph contest

Holograph contest

771.29 USDC • Code4rena • RaymondFam

#15

3xcalibur contest

3xcalibur contest

63.01 USDC • Code4rena • RaymondFam

#28

Juicebox contest

Juicebox contest

63.84 USDC • Code4rena • RaymondFam

#17

The Graph L2 bridge contest

The Graph L2 bridge contest

71.07 USDC • Code4rena • RaymondFam

#14

Blur Exchange contest

Blur Exchange contest

2,520.94 USDC • 1 total finding • Code4rena • RaymondFam

#9

medium

Protocol can be easily rug-pulled by the owner

Sep '22

QuickSwap and StellaSwap contest

QuickSwap and StellaSwap contest

83.99 USDC • Code4rena • RaymondFam

#31

Frax Ether Liquid Staking contest

Frax Ether Liquid Staking contest

12.82 USDC • Code4rena • RaymondFam

#77

VTVL contest

VTVL contest

27.97 USDC • Code4rena • RaymondFam

#69

Art Gobblers contest

Art Gobblers contest

2,830.23 USDC • 1 total finding • Code4rena • RaymondFam

#10

medium

Wrong balanceOf user after minting legendary gobbler

Y2k Finance contest

Y2k Finance contest

89.45 USDC • Code4rena • RaymondFam

#44

PartyDAO contest

PartyDAO contest

118.65 USDC • Code4rena • RaymondFam

#36

FEI and TRIBE Redemption contest

FEI and TRIBE Redemption contest

34.5 USDC • Code4rena • RaymondFam

#10

Canto Dex Oracle contest

Canto Dex Oracle contest

39.22 CANTO • Code4rena • RaymondFam

#12

Nouns Builder contest

Nouns Builder contest

107.23 USDC • Code4rena • RaymondFam

#80

Aug '22

Olympus DAO contest

Olympus DAO contest

86.9 USDC • Code4rena • RaymondFam

#77

Nouns DAO contest

Nouns DAO contest

52.1 USDC • Code4rena • RaymondFam

#38