
Security Researcher
aka TheSavageTeddy | 🚩Vice Captain - @EmuExploit CTF team | DEFCON 32 Finalist | OSCP
High
Total
Medium
Total

Total Earnings
#1267 All Time

Payouts

Top 10

Top 25

Top 50
All
Sherlock
Code4rena
Sep '25
high
All tokens can be drained from Diamond through fake Uniswap pools
medium
Incorrect use of `TAKER_VAULT_ID` in `AdminFacet::transferVaultBalance`
medium
Low ticks may underflow in `tickToTreeIndex` resulting in incorrect tree indexes
medium
Typo in `ViewWalker::down` results in incorrect calculation of fees.
medium
Max assets per owner can be abused to block creating new maker assets
Apr '24
high
Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral
high
Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine
high
Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply
high
Flash loan protection mechanism can be bypassed via self-liquidations
medium
Attacker can frontrun to prevent vaults from being removed from the dNFT owner's position
medium
Incorrect deployment / missing contract will break functionality
Feb '24
Jul '23
May '23
Feb '23