Banner
https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/277c31c8-cdeb-40fc-a578-9fd8ebe10da0.jpg

Zarf

Security Researcher

Blockchain Security Researcher @OpenZeppelin

Contact Me

High

7

Total

Medium

1

Solo

5

Total

$3.76K

Total Earnings

#879 All Time

10x

Payouts

regular

5x

Top 10

regular

7x

Top 25

regular

10x

Top 50

All

Sherlock

Code4rena

Jan '23

Cooler

Cooler

184.54 USDC • 3 total findings • Sherlock • Zarf

#21

high

no-revert-on-transfer ERC20 tokens not supported

high

Borrower can be prevented to repay loan

medium

toggleRoll can be frontrunned

UXD Protocol

UXD Protocol

51.94 USDC • 1 total finding • Sherlock • Zarf

#26

high

Depository can pull USDC from arbitrary addresses upon rebalance

Dec '22

Forgeries contest

Forgeries contest

64.93 USDC • 1 total finding • Code4rena • Zarf

#20

high

Admin does not have to wait to call `lastResortTimelockOwnerClaimNFT()`

Caviar contest

Caviar contest

59.72 USDC • 1 total finding • Code4rena • Zarf

#38

medium

Rounding error in buyQuote might result in free tokens

prePO contest

prePO contest

28.12 USDC • Code4rena • Zarf

#31

NounsDAO

NounsDAO

349.49 USDC • 1 total finding • Sherlock • Zarf

#5

medium

Payer’s funds might be permanently locked in certain cases

Nov '22

Opyn Crab Netting

Opyn Crab Netting

639.85 USDC • 1 total finding • Sherlock • Zarf

#9

high

Contract can be stuck when USDC is paused/recipient blacklisted

Bull v Bear

Bull v Bear

339.37 USDC • 2 total findings • Sherlock • Zarf

#9

high

Checks-Effects-Interaction pattern not followed

medium

Fee-on-transfer tokens not might leak funds

Bond Protocol

Bond Protocol

1,782.51 USDC • 1 total finding • Sherlock • Zarf

#4

medium

Read-only reentrancy in BondFixedTermTeller

Oct '22

Merit Circle

Merit Circle

257.01 USDC • 1 total finding • Sherlock • Zarf

#9

high

Ability to enjoy max benefits while only being locked for the minimum duration