https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/aabf0ced-eebd-4308-bda0-bccc2f0c9053.jpg

Weed0607

Security Researcher

Contact Me

High

9

Total

Medium

8

Total

$1.57K

Total Earnings

#1098 All Time

7x

Payouts

gold

1x

1st Places

regular

3x

Top 10

regular

4x

Top 25

All

Sherlock

Code4rena

Mar '25

Nudge.xyz

Nudge.xyz

0.06 USDC • 1 total finding • Code4rena • Weed0607

#8

medium

Unauthorized Reallocation in `NudgeCampaign::handleReallocation` and Reward Disruption Vulnerability in `NudgeCampaign::invalidateParticipations`

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

0.02 OP • 2 total findings • Sherlock • Weed0607

#64

high

Attackers can steal the funds by creating orders with the same order id.

medium

Incorrect staleness check in the `PythOracle::currentValue` function may return stale price or make the transaction revert.

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

0.38 USDC • 1 total finding • Sherlock • Weed0607

#33

high

`ReputationMarket::buyVotes` function doesn't account `marketFunds` correctly

vVv Launchpad - Investments & Token distribution

vVv Launchpad - Investments & Token distribution

94.59 USDC • 1 total finding • Sherlock • Weed0607

gold

high

Anyone can call `VVVVCTokenDistribution::claim` function by utilizing `ClaimParams` signed by the `signer`

Apr '24

NOYA

NOYA

629.96 USDC + NOYA stars • 10 total findings • Code4rena • Weed0607

#24

high

Incomplete TVL Calculation in `AerodromeConnector::_getPositionTVL` Function.

high

`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`

high

`NoyaValueOracle.getValue` returns an incorrect price when a multi-token route is used

high

Base tokens like USDT, USDC having different decimals on different chains can have their TVL updated incorrectly

high

It is possible to open insolvent position is Silo connector, due to missing check in borrow function

medium

The modifier `onlyExistingRoute` works incorrectly

medium

Attacker can increase the length of `withdrawQueue` by withdrawing 0 amount of tokens frequently

medium

Incorrect modifier condition

medium

Balancer flashloan contract can be DOSed completely by sending 1 wei to it

medium

Dust donation might DOS all connectors to create new holding positions, by preventing removing existing holding positions

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

36.03 USDC • 1 total finding • Code4rena • Weed0607

#46

high

Protocol mints less rsETH on deposit than intended

Oct '23

Badger eBTC Audit + Certora Formal Verification Competition

Badger eBTC Audit + Certora Formal Verification Competition

810.99 USDC • 1 total finding • Code4rena • Weed0607

#10

medium

Redemptions are inconsistent with other cdp's operations