Security Researcher
Web3 Security Researcher
High
Total
Medium
Total Earnings
#1023 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Hats Finance
Jun '24
18.87 USDC • 1 total finding • Code4rena • Timenov
#19
medium
Due to the use of `msg.value` in for loop, anyone can drain all the funds from the `THORChain_Router` contract
May '24
5.96 USDC • 1 total finding • Sherlock • Timenov
#27
high
Attacker can decrease other user token balance.
Apr '24
162.40 USDC • 3 total findings • Sherlock • Timenov
#20
Lender may not be able to close loan or get back lending token.
Lender can not close loan with recipient.
Borrower can keep loan.
2.24 USDC • 1 total finding • Sherlock • Timenov
#55
Attacker can cause revert or decrease rewards.
Mar '24
440.8 USDC • 1 total finding • Code4rena • Timenov
#28
V3Utils.execute() does not have caller validation, leading to stolen NFT positions from users
616.93 USDC • 1 total finding • Code4rena • Timenov
#9
Permit doesnt work with DAI
Feb '24
180 USDC • 1 total finding • Hats • Timenov
#18
low
Event is not emitted
340.29 USDC • 3 total findings • Code4rena • Timenov
#11
Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`
Minter / Staker / Spender roles can never be revoked`..,
Burner role can not be revoked
Jan '24
0.12 USDC • 1 total finding • Code4rena • Timenov
Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.
1.08 USDC • 2 total findings • Code4rena • Timenov
#129
Attack to make ````CurveSubject```` to be a ````HoneyPot````
Unauthorized Access to setCurves Function
Dec '23
21.24 USDC • 1 total finding • Code4rena • Timenov
#67
It may be possible to DoS AuctionHouse by specifying malicious creators
30.41 USDC • 1 total finding • Code4rena • Timenov
#81
LendingTerm::debtCeiling() can return wrong debt as the min() is evaluated incorrectly
Oct '23
0.47 USDC • 1 total finding • Code4rena • Timenov
#111
Auction winner can prevent payments via `safeTransferFrom` callback
Jun '23
28.35 USDC • 1 total finding • Code4rena • Timenov
#77
Incorrectly implemented modifiers in LybraConfigurator.sol allow any address to call functions that are supposed to be restricted
Jan '23
2.59 USDC • 1 total finding • Code4rena • Timenov
#84
Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts