https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

Strapontin

Security Researcher

Contact Me

High

4

Total

Medium

4

Total

$2.77K

Total Earnings

#925 All Time

5x

Payouts

regular

1x

Top 10

regular

4x

Top 25

regular

4x

Top 50

All

Sherlock

CodeHawks

Jan '25

Plaza Finance

Plaza Finance

42.67 USDC • 5 total findings • Sherlock • Strapontin

#54

high

Wrong handling of current auction variable will prevent auctions from ever succeeding, locking user bids and rewards

high

Flashloan attack allows attacker to sandwich `pool::startAuction` to earn an unfair amount of shares

high

Fees handling based on current amount of token in the pool will result in fluctuation of the actual claimed fees

medium

Attacker betting low amount of coupon token for high amount of reserve token will force their bid to stay in the auction if they get blacklisted by couponToken

medium

Auctions succeeding condition does not take into account the claimable fees in the pool. It can result of a drastical reduction of claimable fees if auction succeeds, or cause an auction to fail if the fees are claimed

Dec '24

Alchemix Transmuter

Alchemix Transmuter

501.89 op • 2 total findings • CodeHawks • strapontin

#12

medium

Incorrect Total Assets Calculation in _harvestAndReport Leading to Share Value Manipulation and Irredeemable Assets

low

Old router retains token allowance after update

Oct '24

Flow

Flow

1,781.67 USDC • 1 total finding • CodeHawks • strapontin

#4

low

It is possible to avoid paying the `protocolFee`

Sep '24

Liquid Staking

Liquid Staking

442.15 USDC • 1 total finding • CodeHawks • strapontin

#24

high

No LSTs transfer on node operator withdrawals resulting in stuck funds and loss for node operators

Aug '24

Fjord Token Staking

Fjord Token Staking

0.19 USDC • 1 total finding • CodeHawks • strapontin

#20

medium

[H-01] Auction tokens will be lost forever when auction ends without bids