https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

Yuki

Security Researcher

Independant whitehat expertised in smart contract security. Providing efficient security services - DMs are open.

Contact Me

High

1

Solo

5

Total

Medium

9

Total

$8.44K

Total Earnings

#639 All Time

5x

Payouts

silver

2x

2nd Places

regular

4x

Top 10

regular

5x

Top 25

All

Sherlock

Jul '23

Tokensoft

Tokensoft

1,773.33 USDC • 3 total findings • Sherlock • Yuki

silver

high

User can initialize distribution record multiple times to extend his voting power.

medium

Slightly increasing the vote factor can result to beneficiaries not able to claim their tokens.

medium

Logic error occurs when executing a claim, if the beneficiary was adjusted before.

Index Update

Index Update

697.06 USDC • 1 total finding • Sherlock • Yuki

#5

medium

SetToken can't be unlocked early.

Bond Options

Bond Options

227.91 USDC • 2 total findings • Sherlock • Yuki

#11

high

Malicious user is able to drain the FixedStrikeOptionTeller contract.

medium

Last epoch claimed for the user isn't updated on staking, which can permanently stuck the user from claiming rewards.

Jun '23

Unstoppable

Unstoppable

3,842.94 USDC • 3 total findings • Sherlock • Yuki

silver

high

Wrong accounting of the storage balances results for the protocol to be in debt even when the bad debt is repaid.

high

Stuck funds in the vault duo to wrong logic applied when adding margin to a position.

medium

Order's minimum amount out is calculated wrongly when partially closing a position.

Symmetrical

Symmetrical

1,895.44 USDC • 5 total findings • Sherlock • Yuki

#8

high

Wrong accounting happens when opening a partially filled position, which leads to permanent loss of funds.

medium

Malicious Party A can prevent Party B from emergency closing a position on a market price.

medium

Expired signature can stuck all Party positions in a liquidation state.

medium

Malicious liquidator can get the liquidation fee without finalizing the full liquidation of Party A.

medium

Malicious Party B is able to permanently prevent force closing a position by partially closing dust amounts.