https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/69e53012-6fb7-4c9d-b0e2-d2672524644b.jpg

alexzoid

Providing Certora Formal Verification

alexzoid.com

Contact Me

High

6

Total

Medium

22

Total

$39.91K

Total Earnings

#217 All Time

24x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

bronze

1x

3rd Places

All

Sherlock

Cantina

CodeHawks

Hats Finance

Jan '25

silo-contracts-v2

silo-contracts-v2

189.77 USDC • 1 total finding • Cantina • alexzoid

#20

high

Finding not yet public.

Aave v3.3

Aave v3.3

472.58 USDC • Sherlock • alexzoid

#48

Sep '24

uniswap-v4

uniswap-v4

10,674.03 USDC • Cantina • alexzoid

#11

Flayer

Flayer

84.24 USDC • 3 total findings • Sherlock • alexzoid

#55

medium

setFee() Fails to Update Pool Fee Due to `memory` Keyword

medium

removeFeeExemption() Always Reverts Due to Incorrect Comparison

medium

Incorrect Token Comparison in beforeSwap

Jul '24

Super Boring

Super Boring

1,212.11 USDC • Sherlock • alexzoid

#4

Findings not publicly available for private contests.

May '24

Euler-v2

Euler-v2

18,176 USDC • Cantina • alexzoid

#12

Apr '24

TITLES Publishing Protocol

TITLES Publishing Protocol

141.05 USDC • 7 total findings • Sherlock • alexzoid

#22

high

Incorrect Referrer Address in Fee Routing

medium

Edge Acknowledgment Status Not Persisted in Storage

medium

Misuse of Signature for Edge Status Changes

medium

Inconsistent Edge ID Generation after Work Transfer

medium

Broken Refund Mechanism in Edition Contract

medium

Incorrect Fee Handling in Batch Minting

medium

Incompatibility of Upgradeability Pattern in TitlesGraph Contract

Mar '24

Copra Finance

Copra Finance

1,582.82 USDC • Sherlock • alexzoid

bronze

Findings not publicly available for private contests.

Feb '24

Tokemak

Tokemak

1,700 USDC • Hats • alexzoid

#5

Jan '24

Olympus On-Chain Governance

Olympus On-Chain Governance

139.35 USDC • 1 total finding • Sherlock • alexzoid

#7

medium

Voting Incompatibility with gOHM Contract

Flat Money

Flat Money

41.10 USDC • 1 total finding • Sherlock • alexzoid

#18

medium

When Secondary Offchain Oracle is Invalid, Primary Onchain Will Be Broken Too

Ion Protocol

Ion Protocol

396.4 USDC • Hats • alexzoid

#9

Avail

Avail

67.80 USDC • Sherlock • alexzoid

#19

SYMM IO

SYMM IO

27.10 USDC • Sherlock • alexzoid

#21

Dec '23

DODO V3 update

DODO V3 update

4,000 USDC • 1 total finding • Sherlock • alexzoid

gold

medium

Inability to Re-add `oldToken` After Execution of `D3MakerFreeSlot.setNewTokenAndReplace()`

Footium Update

Footium Update

5.38 USDC • Sherlock • alexzoid

#31

Sep '23

Allo V2

Allo V2

0.09 USDC • 1 total finding • Sherlock • alexzoid

#74

medium

Fee-on-Transfer Tokens Issue in `_fundPool()`

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

7.12 USDC • 6 total findings • CodeHawks • alexzoid

#162

high

Sandwich attack to steal all ERC-20 tokens in the Fees contract

high

Token spending by Uniswap router doesn't get approved

medium

Single-step process for critical ownership transfer is risky

medium

Fixed fee level is used when swap tokens on Uniswap

low

Zero address leads to transaction reverts

low

Missing Events Emitting

Foundry DeFi Stablecoin CodeHawks Audit Contest

Foundry DeFi Stablecoin CodeHawks Audit Contest

25.57 USDC • 7 total findings • CodeHawks • alexzoid

#58

high

Theft of collateral tokens with fewer than 18 decimals

medium

Chainlink oracle will return the wrong price if the aggregator hits `minAnswer`

medium

Anyone can burn **DecentralizedStableCoin** tokens with `burnFrom` function

medium

Lack of fallbacks for price feed oracle

medium

Too many DSC tokens can get minted for fee-on-transfer tokens.

low

Pragma isn't specified correctly which can lead to nonfunction/damaged contract when deployed on Arbitrum

gas

[I-10] Functions not used internally could be marked external

CodeHawks Escrow Contract - Competition Details

CodeHawks Escrow Contract - Competition Details

250.84 USDC • 3 total findings • CodeHawks • alexzoid

#27

medium

Fee-on-transfer tokens aren't supported

gas

Check price != 0 before interacting with IERC20

gas

Use assembly to check for `address(0)`

Beam

Beam

92.79 USDC • Sherlock • alexzoid

#43

May '23

DODO Margin Trading

DODO Margin Trading

116.10 USDC • 1 total finding • Sherlock • alexzoid

silver

high

A Potential "Griefing" Attack Could Drain Funds from `MarginTrading` Contract

Footium

Footium

89.85 USDC • 1 total finding • Sherlock • alexzoid

#25

medium

Club's owner can mint an additional player per season bypassing the limits

Apr '23

Splits

Splits

413.84 USDC • 1 total finding • Sherlock • alexzoid

#6

medium

The potential to bypass the SwapperFactory.isSwapper() check may lead to a loss of funds