https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_1.png

alexfilippov314

Security Researcher

Contact Me

High

26

Total

Medium

30

Total

$582.97K

Total Earnings

#11 All Time

20x

Payouts

gold

1x

1st Places

silver

3x

2nd Places

regular

11x

Top 10

All

Code4rena

Cantina

CodeHawks

Jun '25

Chainlink Rewards

Chainlink Rewards

1.42 USDC • Code4rena • alexfilippov314

#8

Mar '25

interop-portal

interop-portal

5,000 USDC • Cantina • alexfilippov314

silver

Feb '25

Pectra

Pectra

342,159.94 USDC • 3 total findings • Cantina • alexfilippov314

gold

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Dec '24

story-protocol

story-protocol

21,804.83 USDC • 6 total findings • Cantina • alexfilippov314

#15

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Oct '24

Omni Network

Omni Network

58,893.19 USDC • 2 total findings • Cantina • alexfilippov314

#7

medium

Finding not yet public.

medium

Finding not yet public.

Sep '24

uniswap-v4

uniswap-v4

50,888.23 USDC • 3 total findings • Cantina • alexfilippov314

silver

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Aug '24

zetachain-protocol

zetachain-protocol

3,682.96 USDC • 7 total findings • Cantina • alexfilippov314

#8

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

Optimism Superchain

Optimism Superchain

21,374.14 OP • 4 total findings • Code4rena • alexfilippov314

#4

high

An attacker can bypass the challenge period during LPP finalization

high

LPP metadata can be altered after the challenge period is over, allowing incorrect states to be proven

high

The LPP challenge period can cause malicious and freeloader claims to be uncounterable and can also cause freeloader claims to be abused to entrap honest challengers

medium

The `MIPS` doesn't implement `ADD`, `ADDI`, and `SUB` instructions correctly

May '24

Euler-v2

Euler-v2

2,500 USDC • Cantina • alexfilippov314

#21

Apr '24

NOYA

NOYA

135.35 USDC + NOYA stars • 7 total findings • Code4rena • alexfilippov314

#45

high

`SNXConnector.sol` TVL calculation is incorrect.

high

`NoyaValueOracle.getValue` returns an incorrect price when a multi-token route is used

high

Numerous errors when calculating the TVL for the MorphoBlue connector

high

In Dolomite, when opening a borrow position, the holding position in the Registry will never be updated due to the removePosition flag being set to true

medium

The modifier `onlyExistingRoute` works incorrectly

medium

Incorrect modifier condition

medium

Lack of Slippage Controls in retrieveTokensForWithdraw Function

Mar '24

Taiko

Taiko

6,221.51 USDC • 3 total findings • Code4rena • alexfilippov314

#8

high

Users will never be able to withdraw their claimed airdrop fully in ERC20Airdrop2.sol contract

high

Signatures can be replayed in `withdraw()` to withdraw more tokens than the user originally intended.

medium

The decision to return the liveness bond depends solely on the last guardian

Jan '24

Blast

Blast

57,327.12 USDC • 7 total findings • Cantina • alexfilippov314

#4

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Curves

Curves

205.67 USDC • 6 total findings • Code4rena • alexfilippov314

#21

high

Attack to make ````CurveSubject```` to be a ````HoneyPot````

high

Unrestricted claiming of fees due to missing balance updates in `FeeSplitter`

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

A subject creator within a single block can claim holder fees without holding due to unprotected reentrancy path

medium

onBalanceChange causes previously unclaimed rewards to be cleared

Dec '23

stake.link

stake.link

846.36 USDC • 2 total findings • CodeHawks • alexfilippov314

#9

high

A user can steal an already transfered and bridged reSDL lock because of approval

medium

Attacker can exploit lock update logic on secondary chains to increase the amount of rewards sent to a specific secondary chain

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

2.76 USDC • Code4rena • alexfilippov314

#54

Oct '23

NextGen

NextGen

294.66 USDC • 3 total findings • Code4rena • alexfilippov314

#36

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

medium

Bidder Funds Can Become Unrecoverable Due to 1 second Overlap in `participateToAuction()` and `claimAuction()`

medium

Artist signatures can be forged to impersonate the artist behind a collection

zkSync Era

zkSync Era

95.22 USDC • Code4rena • alexfilippov314

#37

Sep '23

Centrifuge

Centrifuge

11,324.58 USDC • 1 total finding • Code4rena • alexfilippov314

silver

medium

`LiquidityPool::requestRedeemWithPermit` transaction can be front run with the different liquidity pool

Aug '23

Dopex

Dopex

15.93 USDC • 1 total finding • Code4rena • alexfilippov314

#116

medium

Change of `fundingDuration` causes "time travel" of `PerpetualAtlanticVault.nextFundingPaymentTimestamp()`

Sparkn

Sparkn

199.37 USDC • 2 total findings • CodeHawks • alexfilippov314

#24

high

The same signature can be used in different `distribution` implementation causing that the caller who owns the signature, can distribute on unauthorized implementations

low

Owner can incorrectly pull funds from contests not yet expired