Security Researcher
Smart contracts
High
Total
Medium
Total Earnings
#708 All Time
Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Dec '24
4.01 OP • 2 total findings • Sherlock • ZanyBonzy
#35
medium
Unspent allowances will permanently dos various protocol operations
PythOracle will rejects non-stale values
6.74 OP • 1 total finding • Sherlock • ZanyBonzy
#60
high
Withdrawal signatures have no deadline or nonce and can be replayed
Nov '24
92.78 USDC • Sherlock • ZanyBonzy
#20
Oct '24
83.85 USDC • 1 total finding • Sherlock • ZanyBonzy
#11
Various use of standard IERC20 approval interface which will fail for certain token types.
421.53 USDC • 1 total finding • Sherlock • ZanyBonzy
#5
`proposalId` is incorrectly hashed, which will lead to signatures failing for EIP-712 compliant signers.
Sep '24
370.31 USDC • 2 total findings • Sherlock • ZanyBonzy
#12
Incentives contracts are initialized by BoostCore, which is missing implementations of certain functions
Protocol doesn't account for tokens that charge fee on transfer, rebasing or similar token types
298.22 USDC • 1 total finding • Sherlock • ZanyBonzy
#37
ERC721Bridgable.sol cannot receive ETH so users cannot claim ETH royalties
Jul '24
190.09 USDC • Sherlock • ZanyBonzy
#91
0.08 USDC • 1 total finding • Sherlock • ZanyBonzy
#64
Lack of support for fee on transfer, rebasing and tokens with balance modifications outside of transfers.
71.06 USDC • 2 total findings • Sherlock • ZanyBonzy
#46
Improperly hardcoded slippage parameters will lead to sandwich attacks
First LP provider of stable pair can DOS the pool
May '24
30.68 USDC • Sherlock • ZanyBonzy
#6
Apr '24
148.12 USDC • 1 total finding • Sherlock • ZanyBonzy
#21
Functions requiring signatures will fail for EIP712 signers
141.61 USDC • 1 total finding • Sherlock • ZanyBonzy
#41
Interest rates keep rising when underlying stablecoin gets paused
Mar '24
67.77 USDC • Sherlock • ZanyBonzy
#17
228.70 USDC • 1 total finding • Sherlock • ZanyBonzy
Stablecoin blocklist feature is ineffective
Feb '24
255.08 USDC • 1 total finding • Sherlock • ZanyBonzy
Functions depending on `_update` might not work due to overflow protection
133.16 USDC • 1 total finding • Sherlock • ZanyBonzy
#9
Restricted admin privileges
1,309.86 USDC • 1 total finding • Sherlock • ZanyBonzy
#4
Mint and sales can be dossed due to lack of safeApprove to 0
Jan '24
3.52 USDC • Sherlock • ZanyBonzy
#33
Dec '23
32.55 USDC • 1 total finding • Sherlock • ZanyBonzy
Possible accounting issues when calculating pool prices.
Nov '23
142.51 USDC • 1 total finding • Sherlock • ZanyBonzy
#8
No check for active L2 Sequencer
1,359.98 USDC • 1 total finding • Sherlock • ZanyBonzy
Lowering the gauge weight can disrupt accounting, potentially leading to both excessive fund distribution and a loss of funds.