Banner
https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/c01a1c33-5d1b-4e21-abce-ed2c7f7be0ab.png

Sentryx

We'll let our portfolio speaks for us 👇 https://github.com/Sentryx-Lab/portfolio

Contact Me

High

13

Total

Medium

1

Solo

19

Total

$7.24K

Total Earnings

#650 All Time

6x

Payouts

regular

2x

Top 10

regular

4x

Top 25

regular

5x

Top 50

All

Sherlock

Code4rena

Nov '24

Nibiru

Nibiru

2,218.8 USDC • 3 total findings • Code4rena • Sentryx

#5

medium

Nibiru's bank coin to EVM balance tracking logic is completely broken for rebasing tokens and would lead to leakage/loss of funds when converting

medium

Nonce can be manipulated by inserting a contract creation EthereumTx message first in an SDK TX with multiple EthereumTX messages

medium

Gas refunds use block gas instead of transaction gas, leading to incorrect refund amounts

Sep '24

Flayer

Flayer

1,299.66 USDC • 4 total findings • Sherlock • Sentryx

#11

high

Wrong division when adjusting `perSecondRate` in compounded factor calculation

high

Tax is resolved on liquidation listings when they are relisted

high

Locker actions affecting utilization rate are not checkpointed

medium

Reserving a listing checkpoints the collection's `compoundFactor` at an intermediary higher compound factor

Jul '24

Velocimeter

Velocimeter

319.55 USDC • 4 total findings • Sherlock • Sentryx

#27

high

Withdrawals, deposits and transfers of tokens for a given user can be griefed by delegating them `MAX_DELEGATES` of tokens

high

Exercising to LP can be manipulated

medium

Miscalculation of team emissions in Minter contract

medium

First liquidity provider of stable pair can DOS it

Jun '24

Size

Size

9.65 USDC • 3 total findings • Code4rena • Sentryx

#55

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

medium

Fragmentation fee is not taken if user compensates with newly created position

medium

Multicall does not work as intended

May '24

Munchables

Munchables

0.01 USDC • 1 total finding • Code4rena • Sentryx

#16

medium

Missing disapproval check in `LockManager.sol::approveUSDPrice` allows simultaneous approval and disapproval of a price proposal

Apr '24

NOYA

NOYA

3,396.91 USDC + NOYA stars • 17 total findings • Code4rena • Sentryx

#4

high

BalancerConnector has incorrect implementation of totalSupply, positionTVL and total TVL will be invalid

high

`BalancerConnector::_getPositionTVL` is calculated incorrectly

high

`SNXConnector.sol` TVL calculation is incorrect.

high

`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`

high

Decreasing a position in PendleConnector will remove it even if there's still a stake at Penpie

high

Numerous errors when calculating the TVL for the MorphoBlue connector

high

SiloConnector `_getPositionTVL` miscalculate the TVL position

medium

LP tokens from Boosted Positions are not included in the TVL calculation of a position held by the MaverickConnector

medium

In the BalancerConnector, unclaimed rewards are not included in the calculation of the connectors TVL

medium

`Keepers` does not implement EIP712 correctly on multiple occasions

medium

Extra rewards are not updated in curve connector when harvestConvexRewards is called

medium

If a curve pool which CurveConnector uses is killed the vault manager can't close the position leading to loss of funds

medium

In the AerodromeConnector, unclaimed rewards are not included in the calculation of the connectors TVL

medium

Some connectors prevents repayment of a borrow position if it doesn't leave the connector solvent or above minimumHealthFactor

medium

Balancer flashloan contract can be DOSed completely by sending 1 wei to it

medium

`depositQueue.queue` in `AccountingManager` can be flooded causing a DoS

medium

Using the same heartbeat for multiple price feeds