https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/bd2b1088-2fe8-4d0e-8568-51d1a6eca2f6.jpg

ZanyBonzy

Security Researcher

Smart contracts

Contact Me

High

5

Total

Medium

15

Total

$5.39K

Total Earnings

#727 All Time

22x

Payouts

silver

1x

2nd Places

regular

8x

Top 10

regular

14x

Top 25

All

Sherlock

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

4.01 OP • 2 total findings • Sherlock • ZanyBonzy

#35

medium

Unspent allowances will permanently dos various protocol operations

medium

PythOracle will rejects non-stale values

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

6.74 OP • 1 total finding • Sherlock • ZanyBonzy

#60

high

Withdrawal signatures have no deadline or nonce and can be replayed

Nov '24

Telcoin Update #2

Telcoin Update #2

92.78 USDC • Sherlock • ZanyBonzy

#20

Oct '24

AXION

AXION

83.85 USDC • 1 total finding • Sherlock • ZanyBonzy

#11

medium

Various use of standard IERC20 approval interface which will fail for certain token types.

predict.fun lending market

predict.fun lending market

421.53 USDC • 1 total finding • Sherlock • ZanyBonzy

#5

medium

`proposalId` is incorrectly hashed, which will lead to signatures failing for EIP-712 compliant signers.

Sep '24

Boost Core Incentive Protocol

Boost Core Incentive Protocol

370.31 USDC • 2 total findings • Sherlock • ZanyBonzy

#12

high

Incentives contracts are initialized by BoostCore, which is missing implementations of certain functions

medium

Protocol doesn't account for tokens that charge fee on transfer, rebasing or similar token types

Flayer

Flayer

298.22 USDC • 1 total finding • Sherlock • ZanyBonzy

#37

high

ERC721Bridgable.sol cannot receive ETH so users cannot claim ETH royalties

Jul '24

MakerDAO Endgame

MakerDAO Endgame

190.09 USDC • Sherlock • ZanyBonzy

#91

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

0.08 USDC • 1 total finding • Sherlock • ZanyBonzy

#64

medium

Lack of support for fee on transfer, rebasing and tokens with balance modifications outside of transfers.

Velocimeter

Velocimeter

71.06 USDC • 2 total findings • Sherlock • ZanyBonzy

#46

high

Improperly hardcoded slippage parameters will lead to sandwich attacks

medium

First LP provider of stable pair can DOS the pool

May '24

Kwenta x Perennial Integration Update

Kwenta x Perennial Integration Update

30.68 USDC • Sherlock • ZanyBonzy

#6

Apr '24

TITLES Publishing Protocol

TITLES Publishing Protocol

148.12 USDC • 1 total finding • Sherlock • ZanyBonzy

#21

medium

Functions requiring signatures will fail for EIP712 signers

Zivoe

Zivoe

141.61 USDC • 1 total finding • Sherlock • ZanyBonzy

#41

medium

Interest rates keep rising when underlying stablecoin gets paused

Mar '24

vVv Vesting & Staking

vVv Vesting & Staking

67.77 USDC • Sherlock • ZanyBonzy

#17

Telcoin Platform Audit Update

Telcoin Platform Audit Update

228.70 USDC • 1 total finding • Sherlock • ZanyBonzy

silver

medium

Stablecoin blocklist feature is ineffective

Feb '24

Jala Swap

Jala Swap

255.08 USDC • 1 total finding • Sherlock • ZanyBonzy

#6

medium

Functions depending on `_update` might not work due to overflow protection

Napier

Napier

133.16 USDC • 1 total finding • Sherlock • ZanyBonzy

#9

medium

Restricted admin privileges

Smilee Finance

Smilee Finance

1,309.86 USDC • 1 total finding • Sherlock • ZanyBonzy

#4

medium

Mint and sales can be dossed due to lack of safeApprove to 0

Jan '24

SYMM IO

SYMM IO

3.52 USDC • Sherlock • ZanyBonzy

#33

Dec '23

Olympus RBS 2.0

Olympus RBS 2.0

32.55 USDC • 1 total finding • Sherlock • ZanyBonzy

#17

medium

Possible accounting issues when calculating pool prices.

Nov '23

Notional Update #4

Notional Update #4

142.51 USDC • 1 total finding • Sherlock • ZanyBonzy

#8

medium

No check for active L2 Sequencer

Convergence

Convergence

1,359.98 USDC • 1 total finding • Sherlock • ZanyBonzy

#8

high

Lowering the gauge weight can disrupt accounting, potentially leading to both excessive fund distribution and a loss of funds.