https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/d4408b41-4e6c-48c7-b32f-e0eda9b99fb0.jpg

StErMi

Security Researcher

#web3 dev + auditor | @SpearbitDAO security researcher, @TheSecureum bootcamp0, @code4rena + @sherlockdefi + @immunefi bug hunter

Contact Me

High

4

Total

Medium

15

Total

$33.23K

Total Earnings

#251 All Time

16x

Payouts

gold

1x

1st Places

regular

4x

Top 10

regular

6x

Top 25

All

Sherlock

Code4rena

Cantina

May '24

Aave v3.1 Competition

Aave v3.1 Competition

14,285.71 GHO • 1 total finding • Cantina • StErMi

gold

medium

Finding not yet public.

Feb '24

eigenlayer-contracts

eigenlayer-contracts

1,500 USDC • Cantina • StErMi

#4

Jan '24

Blast

Blast

10,000 USDC • Cantina • StErMi

#29

incentive-contracts

incentive-contracts

4,411.93 USDC • 4 total findings • Cantina • StErMi

#7

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Feb '23

OpenQ

OpenQ

153.65 USDC • 2 total findings • Sherlock • StErMi

#30

high

funder can frontrun the claim asking for a refund. The claimant will be able to finish the claim operation without getting any reward back

medium

`setPayoutSchedule` and `setPayoutScheduleFixed` will revert if `_payoutSchedule` has a length lower compared to `tierWinners`

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

330.94 USDC • 2 total findings • Code4rena • StErMi

#16

medium

Buyer on secondary NFT market can lose fund if they buy a NFT that is already used to claim the reward

medium

Users may not claim Erc1155 rewards when the Quest has ended

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

22.72 USDC • 1 total finding • Code4rena • StErMi

#57

high

Arbitrary transactions possible due to insufficient signature validation

Jul '22

Golom contest

Golom contest

35.17 USDC • Code4rena • StErMi

#86

Jun '22

Putty contest

Putty contest

78.9 USDC • 1 total finding • Code4rena • StErMi

#53

medium

`fillOrder()` and `exercise()` may lock Ether sent to the contract, forever

Nibbl contest

Nibbl contest

45.83 USDC • Code4rena • StErMi

#39

Yieldy contest

Yieldy contest

527.59 USDC • 2 total findings • Code4rena • StErMi

#21

medium

Functions in the `BatchRequests` contract revert for removed contract addresses

medium

Unsecure `transferFrom`

Illuminate contest

Illuminate contest

231.76 USDC • 1 total finding • Code4rena • StErMi

#35

high

ERC5095 redeem/withdraw does not update allowances

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

91.44 USDC • Code4rena • StErMi

#42

May '22

Rubicon contest

Rubicon contest

77.36 USDC • 2 total findings • Code4rena • StErMi

#72

medium

No cap on fees can result in a DOS in BathToken.withdraw()

medium

Admin rug vectors

Sturdy contest

Sturdy contest

1,404.78 USDC • 3 total findings • Code4rena • StErMi

#9

high

The check for value transfer success is made after the return statement in _withdrawFromYieldPool of LidoVault

medium

Possible lost msg.value

medium

`processYield()` and `distributeYield()` may run out of gas and revert due to long list of extra rewards/yields

Jan '22

XDEFI contest

XDEFI contest

30.27 USDC • Code4rena • StErMi

#29