https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/4f147ad4-d017-4161-a2c0-a6a8658729a3.jpg

Timenov

Security Researcher

Web3 Security Researcher

Contact Me

High

12

Total

Medium

7

Total

$1.85K

Total Earnings

#1051 All Time

15x

Payouts

regular

1x

Top 10

regular

5x

Top 25

regular

7x

Top 50

All

Sherlock

Code4rena

Hats Finance

Jun '24

Thorchain

Thorchain

18.87 USDC • 1 total finding • Code4rena • Timenov

#19

medium

Due to the use of `msg.value` in for loop, anyone can drain all the funds from the `THORChain_Router` contract

May '24

Elfi

Elfi

5.96 USDC • 1 total finding • Sherlock • Timenov

#27

high

Attacker can decrease other user token balance.

Apr '24

Teller Finance

Teller Finance

162.40 USDC • 3 total findings • Sherlock • Timenov

#20

high

Lender may not be able to close loan or get back lending token.

high

Lender can not close loan with recipient.

high

Borrower can keep loan.

Zivoe

Zivoe

2.24 USDC • 1 total finding • Sherlock • Timenov

#55

high

Attacker can cause revert or decrease rewards.

Mar '24

Revert Lend

Revert Lend

440.8 USDC • 1 total finding • Code4rena • Timenov

#28

high

V3Utils.execute() does not have caller validation, leading to stolen NFT positions from users

PoolTogether

PoolTogether

616.93 USDC • 1 total finding • Code4rena • Timenov

#9

medium

Permit doesnt work with DAI

Feb '24

Tokemak

Tokemak

180 USDC • 1 total finding • Hats • Timenov

#18

low

Event is not emitted

AI Arena

AI Arena

340.29 USDC • 3 total findings • Code4rena • Timenov

#11

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

Minter / Staker / Spender roles can never be revoked`..,

medium

Burner role can not be revoked

Jan '24

Decent

Decent

0.12 USDC • 1 total finding • Code4rena • Timenov

#55

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

Curves

Curves

1.08 USDC • 2 total findings • Code4rena • Timenov

#129

high

Attack to make ````CurveSubject```` to be a ````HoneyPot````

high

Unauthorized Access to setCurves Function

Dec '23

Revolution Protocol

Revolution Protocol

21.24 USDC • 1 total finding • Code4rena • Timenov

#67

medium

It may be possible to DoS AuctionHouse by specifying malicious creators

Ethereum Credit Guild

Ethereum Credit Guild

30.41 USDC • 1 total finding • Code4rena • Timenov

#81

medium

LendingTerm::debtCeiling() can return wrong debt as the min() is evaluated incorrectly

Oct '23

NextGen

NextGen

0.47 USDC • 1 total finding • Code4rena • Timenov

#111

medium

Auction winner can prevent payments via `safeTransferFrom` callback

Jun '23

Lybra Finance

Lybra Finance

28.35 USDC • 1 total finding • Code4rena • Timenov

#77

high

Incorrectly implemented modifiers in LybraConfigurator.sol allow any address to call functions that are supposed to be restricted

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

2.59 USDC • 1 total finding • Code4rena • Timenov

#84

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts