https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/6faacc4c-76fa-4ba1-8ffd-89726088aa2f.jpg

audithare

Security Researcher

Expert in Blockchain / Smart Contract Security and Formal Methods. Independent Software Engineering Consultant.

Contact Me

High

7

Total

Medium

5

Total

$8.75K

Total Earnings

#592 All Time

9x

Payouts

gold

1x

1st Places

regular

3x

Top 10

regular

5x

Top 25

All

Sherlock

Code4rena

Apr '24

Renzo

Renzo

18.2 USDC • 1 total finding • Code4rena • CodeWasp

#41

medium

Pending withdrawals prevent safe removal of collateral assets

DYAD

DYAD

4.1 USDC • 2 total findings • Code4rena • CodeWasp

#106

high

Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine

high

Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply

Panoptic

Panoptic

32.96 USDC • Code4rena • CodeWasp

#18

Mar '24

Axis Finance

Axis Finance

5.04 USDC • 1 total finding • Sherlock • audithare

#28

high

`Auctioneer.auction()` always overwrites first auction's parameters

Zap Protocol

Zap Protocol

82.08 USDC • 1 total finding • Sherlock • audithare

#9

medium

Blacklisted users allowed to claim USDC

PoolTogether

PoolTogether

577.45 USDC • 1 total finding • Code4rena • CodeWasp

#10

medium

Funds locked due to missing transfer check

Feb '24

UniStaker Infrastructure

UniStaker Infrastructure

7,783.56 USDC • Code4rena • CodeWasp

gold
Althea Liquid Infrastructure

Althea Liquid Infrastructure

7.18 USDC • 1 total finding • Code4rena • CodeWasp

#34

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

AI Arena

AI Arena

242.1 USDC • 5 total findings • Code4rena • CodeWasp

#23

high

Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)

medium

Burner role can not be revoked