Security Researcher
Security Researcher @code4rena @immunefi
High
Total
Medium
Total Earnings
#306 All Time
Payouts
1st Places
Top 10
Top 25
All
Sherlock
Code4rena
Jun '23
627.32 USDC • 1 total finding • Sherlock • auditor0517
#13
high
`ArrakisV2Router.addLiquidityPermit2()` uses an uninitialized `isToken0Weth`.
9,090.03 USDC • 3 total findings • Code4rena • auditor0517
In `LlamaRelativeQuorum`, the governance result might be incorrect as it counts the wrong approval/disapproval.
Anyone can change approval/disapproval threshold for any action using LlamaRelativeQuorum strategy.
medium
LlamaPolicy could be DOS by creating large amount of actions.
Apr '23
4,753.89 USDC • 1 total finding • Code4rena • auditor0517
#4
`validateSignature(...)` in `EllipticCurve` mixes up Jacobian and projective coordinates
Mar '23
4.68 USDC • 2 total findings • Code4rena • auditor0517
#120
Staking, unstaking and rebalanceToWeight can be sandwiched (Mainly rETH deposit )
`WstEth` derivative assumes a ~1=1 peg of stETH to ETH
1,440.31 USDC • Code4rena • auditor0517
#10
2.35 USDC • 1 total finding • Sherlock • auditor0517
#59
Wrong update of `ownerToRollOverQueueIndex`
2,974.43 USDC • 2 total findings • Code4rena • auditor0517
Underflow of `lpPosition.points` during withdrawLP causes huge reward minting
Updating a pool's total points doesn't affect existing stake positions for rewards calculation
619.34 USDC • 1 total finding • Code4rena • auditor0517
#11
`LotteryMath.calculateNewProfit` returns wrong profit when there is no jackpot winner
Sep '22
1,858.21 USDC • 1 total finding • Code4rena • auditor0517
Can Recover Gobblers Burnt In Legendary Mint
73.23 USDC • 1 total finding • Code4rena • auditor0517
#47
Incorrect handling of pricefeed.decimals()
Aug '22
38.84 USDC • Code4rena • auditor0517
#39
107.67 USDC • 1 total finding • Code4rena • auditor0517
#32
ERROR IN UPDATING **_checkpoint** IN THE **increaseUnlockTime** FUNCTION
2,774.28 USDC • 2 total findings • Code4rena • auditor0517
#5
FraxlendPair.changeFee() doesn't update interest before changing fee.
Wrong percent for `FraxlendPairCore.dirtyLiquidationFee`.
84.09 USDC • 1 total finding • Code4rena • auditor0517
#27
Possible to bypass saleConfig.limitPerAccount
165.63 USDC • 1 total finding • Code4rena • auditor0517
#36
Builder can halve the interest paid to a community owner due to arithmetic rounding
Jul '22
186.56 USDC • Code4rena • auditor0517
#58
106.88 USDC • 1 total finding • Code4rena • auditor0517
#26
Interface definition error
81.3 USDC • 1 total finding • Code4rena • auditor0517
#79
```migrateFractions``` may be called more than once by the same user which may lead to loss of tokens for other users
Jun '22
727.39 USDC • 3 total findings • Code4rena • auditor0517
#24
Fee is being deducted when Put is expired and not when it is exercised.
`fillOrder()` and `exercise()` may lock Ether sent to the contract, forever
Options with a small strike price will round down to 0 and can prevent assets to be withdrawn
553.3 USDC • 3 total findings • Code4rena • auditor0517
Redeemer.redeem() for Element withdraws PT to wrong address.
Funds may be stuck when `redeeming` for Illuminate
[H-05] Not minting iPTs for lenders in several lend functions
276.92 USDC • 1 total finding • Code4rena • auditor0517
#29
Calling `unstake()` can cause locked funds
141.86 USDC • Code4rena • auditor0517
#52