https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/a7092172-583b-4323-a809-b4aeea274bdc.jpg

_eperezok

Security Researcher

Computer Engineering @ITBA

Contact Me

High

10

Total

Medium

10

Total

$1.94K

Total Earnings

#1099 All Time

8x

Payouts

regular

1x

Top 10

regular

1x

Top 25

regular

3x

Top 50

All

Code4rena

Feb '24

AI Arena

AI Arena

32.48 USDC • 6 total findings • Code4rena • _eperezok

#99

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Fighters cannot be minted after the initial generation due to uninitialized `numElements` mapping

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

Minter / Staker / Spender roles can never be revoked`..,

medium

DoS in `MergingPool::claimRewards` function and potential DoS in `RankedBattle::claimNRN` function if called after a significant amount of rounds passed.

medium

Fighter created by mintFromMergingPool can have arbitrary weight and element

Jan '24

Curves

Curves

1,241.3 USDC • 6 total findings • Code4rena • _eperezok

#9

high

Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale

high

Attack to make ````CurveSubject```` to be a ````HoneyPot````

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

medium

Theft of holder fees when `holderFeePercent` was positive and is set to zero

Dec '23

Revolution Protocol

Revolution Protocol

140.82 USDC • 3 total findings • Code4rena • _eperezok

#40

medium

Violation of ERC-721 Standard in VerbsToken:tokenURI Implementation

medium

Bidder can use donations to get VerbsToken from auction that already ended.

medium

It may be possible to DoS AuctionHouse by specifying malicious creators

Oct '23

NextGen

NextGen

1.09 USDC • 3 total findings • Code4rena • _eperezok

#107

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

high

Attacker can reenter to mint all the collection supply

medium

Auction winner can prevent payments via `safeTransferFrom` callback

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

0.11 USDC • 1 total finding • Code4rena • _eperezok

#62

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

Aug '23

Dopex

Dopex

0.15 USDC • 1 total finding • Code4rena • _eperezok

#124

high

The peg stability module can be compromised by forcing lowerDepeg to revert.

veRWA

veRWA

9.82 USDC • Code4rena • _eperezok

#52

May '23

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

511.61 USDC • Code4rena • _eperezok

#34