https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_1.png

UbiquitousComputing

Security Researcher

Contact Me

High

5

Total

Medium

5

Total

$291.00

Total Earnings

#1650 All Time

3x

Payouts

regular

1x

Top 10

regular

2x

Top 25

regular

2x

Top 50

All

Sherlock

Code4rena

Mar '24

Zap Protocol

Zap Protocol

9.97 USDC • 1 total finding • Sherlock • UbiquitousComputing

#12

high

If the token for `Vesting` is BNB, re-entrancy will allow double-claiming, draining the contract

Jan '24

Curves

Curves

25.88 USDC • 8 total findings • Code4rena • UbiquitousComputing

#74

high

Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale

high

Attack to make ````CurveSubject```` to be a ````HoneyPot````

high

Unrestricted claiming of fees due to missing balance updates in `FeeSplitter`

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

onBalanceChange causes previously unclaimed rewards to be cleared

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

medium

If a user sets their curve token symbol as the default one plus the next token counter instance it will render the whole default naming functionality obsolete

Truflation

Truflation

255.72 USDC • 1 total finding • Sherlock • UbiquitousComputing

#6

medium

Total vesting time is `initialReleasePeriod + cliff + period`, however admin cannot cancel vesting after just `period` has passed