Security Researcher
Web3 Security.
High
Total
Medium
Total Earnings
#1517 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
CodeHawks
Nov '24
7.88 USDC • 1 total finding • Sherlock • alexbabits
#54
high
Buyer doesn't receive NFT that they should get in `buyOrder.sellNFT()`
Jan '24
228.10 USDC • 2 total findings • Sherlock • alexbabits
#9
medium
Frontrunning `rewardValidators()` for instant rewards
Validator cannot set new address if more than 300 unstakes in it's array
2.64 USDC • 1 total finding • Sherlock • alexbabits
Array swap and pop method during burn() leads to complete loss of user rewards and breaks mint()
0.01 USDC • 3 total findings • Code4rena • alexbabits
#136
Unauthorized Access to setCurves Function
onBalanceChange causes previously unclaimed rewards to be cleared
Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.
Dec '23
20.37 USDC • 3 total findings • CodeHawks • alexbabits
#53
Looping over unbounded `pendingStakes` array can lead to permanent DoS and frozen funds
low
Anyone with TST tokens can monitor the mempool and frontrun mint/burn functions to get EUROs rewards without even staking.
Incorrectly set `version` for `SmartVaultV3` breaks off-chain integration
1.34 USDC • 1 total finding • Code4rena • alexbabits
#75
Bidder can use donations to get VerbsToken from auction that already ended.
Nov '23
44.92 USDC • Code4rena • alexbabits
#10