https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/4fb5e571-9ec1-4793-83e2-5eefe49bfdfa.jpg

auditor0517

Security Researcher

Security Researcher @code4rena @immunefi

Contact Me

High

18

Total

Medium

9

Total

$26.69K

Total Earnings

#312 All Time

22x

Payouts

gold

1x

1st Places

regular

5x

Top 10

regular

10x

Top 25

All

Sherlock

Code4rena

Jun '23

Arrakis

Arrakis

627.32 USDC • 1 total finding • Sherlock • auditor0517

#13

high

`ArrakisV2Router.addLiquidityPermit2()` uses an uninitialized `isToken0Weth`.

Llama

Llama

9,090.03 USDC • 3 total findings • Code4rena • auditor0517

gold

high

In `LlamaRelativeQuorum`, the governance result might be incorrect as it counts the wrong approval/disapproval.

high

Anyone can change approval/disapproval threshold for any action using LlamaRelativeQuorum strategy.

medium

LlamaPolicy could be DOS by creating large amount of actions.

Apr '23

ENS Contest

ENS Contest

4,753.89 USDC • 1 total finding • Code4rena • auditor0517

#4

medium

`validateSignature(...)` in `EllipticCurve` mixes up Jacobian and projective coordinates

Mar '23

Asymmetry contest

Asymmetry contest

4.68 USDC • 2 total findings • Code4rena • auditor0517

#120

high

Staking, unstaking and rebalanceToWeight can be sandwiched (Mainly rETH deposit )

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

Polynomial Protocol contest

Polynomial Protocol contest

1,440.31 USDC • Code4rena • auditor0517

#10

Y2K

Y2K

2.35 USDC • 1 total finding • Sherlock • auditor0517

#59

high

Wrong update of `ownerToRollOverQueueIndex`

Neo Tokyo contest

Neo Tokyo contest

2,974.43 USDC • 2 total findings • Code4rena • auditor0517

#4

high

Underflow of `lpPosition.points` during withdrawLP causes huge reward minting

high

Updating a pool's total points doesn't affect existing stake positions for rewards calculation

Wenwin contest

Wenwin contest

619.34 USDC • 1 total finding • Code4rena • auditor0517

#11

high

`LotteryMath.calculateNewProfit` returns wrong profit when there is no jackpot winner

Sep '22

Art Gobblers contest

Art Gobblers contest

1,858.21 USDC • 1 total finding • Code4rena • auditor0517

#13

high

Can Recover Gobblers Burnt In Legendary Mint

Y2k Finance contest

Y2k Finance contest

73.23 USDC • 1 total finding • Code4rena • auditor0517

#47

high

Incorrect handling of pricefeed.decimals()

Aug '22

Nouns DAO contest

Nouns DAO contest

38.84 USDC • Code4rena • auditor0517

#39

FIAT DAO veFDT contest

FIAT DAO veFDT contest

107.67 USDC • 1 total finding • Code4rena • auditor0517

#32

medium

ERROR IN UPDATING **_checkpoint** IN THE **increaseUnlockTime** FUNCTION

Fraxlend (Frax Finance) contest

Fraxlend (Frax Finance) contest

2,774.28 USDC • 2 total findings • Code4rena • auditor0517

#5

medium

FraxlendPair.changeFee() doesn't update interest before changing fee.

medium

Wrong percent for `FraxlendPairCore.dirtyLiquidationFee`.

Foundation Drop contest

Foundation Drop contest

84.09 USDC • 1 total finding • Code4rena • auditor0517

#27

medium

Possible to bypass saleConfig.limitPerAccount

Rigor Protocol contest

Rigor Protocol contest

165.63 USDC • 1 total finding • Code4rena • auditor0517

#36

high

Builder can halve the interest paid to a community owner due to arithmetic rounding

Jul '22

Golom contest

Golom contest

186.56 USDC • Code4rena • auditor0517

#58

Swivel v3 contest

Swivel v3 contest

106.88 USDC • 1 total finding • Code4rena • auditor0517

#26

medium

Interface definition error

Fractional v2 contest

Fractional v2 contest

81.3 USDC • 1 total finding • Code4rena • auditor0517

#79

high

```migrateFractions``` may be called more than once by the same user which may lead to loss of tokens for other users

Jun '22

Putty contest

Putty contest

727.39 USDC • 3 total findings • Code4rena • auditor0517

#24

high

Fee is being deducted when Put is expired and not when it is exercised.

medium

`fillOrder()` and `exercise()` may lock Ether sent to the contract, forever

medium

Options with a small strike price will round down to 0 and can prevent assets to be withdrawn

Illuminate contest

Illuminate contest

553.3 USDC • 3 total findings • Code4rena • auditor0517

#24

high

Redeemer.redeem() for Element withdraws PT to wrong address.

high

Funds may be stuck when `redeeming` for Illuminate

high

[H-05] Not minting iPTs for lenders in several lend functions

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

276.92 USDC • 1 total finding • Code4rena • auditor0517

#29

high

Calling `unstake()` can cause locked funds

Connext Amarok contest

Connext Amarok contest

141.86 USDC • Code4rena • auditor0517

#52