https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

Soosh

Security Researcher

Contact Me

High

9

Total

Medium

10

Total

$87.84K

Total Earnings

#108 All Time

16x

Payouts

gold

2x

1st Places

regular

3x

Top 10

regular

7x

Top 25

All

Code4rena

May '23

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

689.32 USDC • Code4rena • Soosh

#29

Jan '23

Reserve contest

Reserve contest

8,940.36 USDC • 3 total findings • Code4rena • Soosh

#6

medium

Loss of staking yield for stakers when another user stakes in pause/frozen state

medium

In case that `unstakingDelay` is decreased, users who have previously unstaked would have to wait more than `unstakingDelay` for new unstakes

medium

Unsafe downcasting in `issue(...)` can be exploited to cause permanent DoS

Dec '22

Forgeries contest

Forgeries contest

24.99 USDC • 1 total finding • Code4rena • Soosh

#24

high

Admin does not have to wait to call `lastResortTimelockOwnerClaimNFT()`

Escher contest

Escher contest

30.15 USDC • 2 total findings • Code4rena • Soosh

#59

medium

ETH will get stuck if all NFTs do not get sold.

medium

selfdestruct() will not be available after EIP-4758

Oct '22

zkSync v2 contest

zkSync v2 contest

70,985.01 USDC • 1 total finding • Code4rena • Soosh

gold

medium

`BLOCK_PERIOD` is incorrect

Blur Exchange contest

Blur Exchange contest

3,283.97 USDC • 2 total findings • Code4rena • Soosh

gold

high

StandardPolicyERC1155.sol returns amount == 1 instead of amount == order.amount

medium

Protocol can be easily rug-pulled by the owner

Sep '22

Frax Ether Liquid Staking contest

Frax Ether Liquid Staking contest

67.17 USDC • 1 total finding • Code4rena • Soosh

#38

medium

frxETHMinter.depositEther may run out of gas, leading to lost ETH

VTVL contest

VTVL contest

0.74 USDC • 1 total finding • Code4rena • Soosh

#81

medium

Supply cap of VariableSupplyERC20Token is not properly enforced

Nouns Builder contest

Nouns Builder contest

1,877.64 USDC • 2 total findings • Code4rena • Soosh

#15

high

`_transferFrom()` can be used to indefinitely increase voting power.

high

Use can get unlimited votes

Aug '22

Nouns DAO contest

Nouns DAO contest

35.44 USDC • Code4rena • Soosh

#41

Rigor Protocol contest

Rigor Protocol contest

40.62 USDC • Code4rena • Soosh

#68

Jul '22

Golom contest

Golom contest

35.17 USDC • Code4rena • Soosh

#86

Swivel v3 contest

Swivel v3 contest

73.08 USDC • Code4rena • Soosh

#40

Jun '22

Canto v2 contest

Canto v2 contest

70.47 USDC • 1 total finding • Code4rena • Soosh

#23

medium

Stableswap - Deadline do not work

Illuminate contest

Illuminate contest

146.11 USDC • 1 total finding • Code4rena • Soosh

#43

high

Illuminate PT redeeming allows for burning from other accounts

Canto contest

Canto contest

1,537.16 USDC • 4 total findings • Code4rena • Soosh

#20

high

Stealing Wrapped Manifest in WETH.sol

high

Anyone can set the `baseRatePerYear` after the `updateFrequency` has passed

high

Anyone can create Proposal Unigov Proposal-Store.sol

high

Comptroller uses the wrong address for the WETH contract