https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_1.png

aphak5010

Security Researcher

Contact Me

High

4

Total

Medium

17

Total

$12.30K

Total Earnings

#513 All Time

10x

Payouts

regular

5x

Top 10

regular

7x

Top 25

regular

10x

Top 50

All

Sherlock

Code4rena

Nov '22

Canto contest

Canto contest

73.58 CANTO • Code4rena • aphak5010

#10

Redacted Cartel contest

Redacted Cartel contest

3,824.26 USDC • 3 total findings • Code4rena • aphak5010

#7

medium

Deposit Feature Of The Vault Will Break If Update To A New Platform

medium

Anyone can call AutoPxGmx.compound and perform sandwich attacks with control parameters

medium

AutoPxGmx.maxWithdraw and AutoPxGlp.maxWithdraw functions calculate asset amount that is too big and cannot be withdrawn

Telcoin

Telcoin

30.30 USDC • 1 total finding • Sherlock • aphak5010

#6

medium

Usage of transfer function without checking return value can result in failure to rescue ERC20 tokens

Buffer Finance

Buffer Finance

6.52 USDC • 1 total finding • Sherlock • aphak5010

#12

medium

Certain ERC20 tokens can get locked in BufferBinaryPool

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

3,013.55 USDC • 9 total findings • Code4rena • aphak5010

#7

high

Incorrect accounting in SyndicateRewardsProcessor results in any LP token holder being able to steal other LP tokens holder's ETH from the fees and MEV vault.

high

Sender transferring GiantMevAndFeesPool tokens can afterward experience pool DOS and orphaning of future rewards

medium

GiantPool batchRotateLPTokens function: Minimum balance for rotating LP Tokens should by dynamically calculated

medium

GiantMevAndFeesPool.previewAccumulatedETH function: "accumulated" variable is not updated correctly in for loop leading to result that is too low

medium

Calling `updateNodeRunnerWhitelistStatus` function always reverts

medium

Freezing of funds - Hacker can prevent users withdraws in giant pools

medium

GiantPool should not check ETH amount on withdrawal

medium

Withdrawing wrong LPToken from GiantPool leads to loss of funds

medium

OwnableSmartWallet: Multiple approvals can lead to unwanted ownership transfers

Blur Exchange contest

Blur Exchange contest

22.22 USDC • Code4rena • aphak5010

#30

LooksRare Aggregator contest

LooksRare Aggregator contest

36.34 USDC • Code4rena • aphak5010

#24

Debt DAO contest

Debt DAO contest

5,199.79 USDC • 7 total findings • Code4rena • aphak5010

#7

high

Non-existing revenue contract can be passed to claimRevenue to send all tokens to treasury

high

Repaying a line of credit with a higher than necessary claimed revenue amount will force the borrower into liquidation

medium

Lender can trade claimToken in a malicious way to steal the borrower's money via claimAndRepay() in SpigotedLine by using malicious zeroExTradeData

medium

Mutual consent cannot be revoked and stays valid forever

medium

Mistakenly sent eth could be locked

medium

Variable balance ERC20 support

medium

Borrower/Lender excessive ETH not refunded and permanently locked in protocol

Oct '22

Inverse Finance contest

Inverse Finance contest

55.74 USDC • Code4rena • aphak5010

#41

3xcalibur contest

3xcalibur contest

34.98 USDC • Code4rena • aphak5010

#33