https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

ayeslick

Security Researcher

Contact Me

High

9

Total

Medium

24

Total

$13.35K

Total Earnings

#463 All Time

22x

Payouts

bronze

1x

3rd Places

regular

2x

Top 10

regular

9x

Top 25

All

Sherlock

Code4rena

CodeHawks

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

20.36 USDC • 3 total findings • CodeHawks • ayeslick

#120

high

Lender can Sandwich a borrower to seize his collateral

medium

The `borrow` and `refinance` functions can be front-run by the pool lender to set high interest rates

low

Operator can prevent customers from borrowing from a given pool

CodeHawks Escrow Contract - Competition Details

CodeHawks Escrow Contract - Competition Details

41.06 USDC • 2 total findings • CodeHawks • ayeslick

#50

medium

[H-01] Lack of emergency withdraw function when no arbiter is set

medium

High - Funds can be lost if any participant is blacklisted

Tapioca DAO

Tapioca DAO

1,273.01 USDC • 6 total findings • Code4rena • ayeslick

#39

high

Reentrancy in `USDO.flashLoan()`, enabling an attacker to borrow unlimited USDO exceeding the max borrow limit

high

Ability to steal user funds and increase collateral share infinitely in BigBang and Singularity

medium

BigBang and Singularity should not pause repay() and liquidate()

medium

Cannot use CurveSwapper when calling compound due to mismatched data parameter

medium

`MagnetarV2#burst` double counts `msg.value` for `TOFT_WRAP` operation, making the transaction revert unless the user overpays

medium

all deposit and withdraw function in Convex and Curve nativeLP Strategy, apply slippage on internal pricing; which call real-time on chain price from Curve directly and subject to MEV

Jan '23

Popcorn contest

Popcorn contest

62.44 USDC • 2 total findings • Code4rena • ayeslick

#72

medium

Anyone can reset fees to 0 value when Vault is deployed

medium

`quitPeriod` is effectively always just `1 day`

Astaria contest

Astaria contest

95.46 USDC • 1 total finding • Code4rena • ayeslick

#49

medium

Improper Approval Mechanism of Clearing House

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

22.72 USDC • 1 total finding • Code4rena • ayeslick

#57

high

Arbitrary transactions possible due to insufficient signature validation

Dec '22

Forgeries contest

Forgeries contest

45.71 USDC • Code4rena • ayeslick

#21

prePO contest

prePO contest

210.78 USDC • 1 total finding • Code4rena • ayeslick

#26

high

A whale user is able to cause freeze of funds of other users by bypassing withdraw limit

Nov '22

ParaSpace contest

ParaSpace contest

835.72 USDC • 1 total finding • Code4rena • ayeslick

#27

medium

Value can be stuck in Adapters

Debt DAO contest

Debt DAO contest

1,938.11 USDC • 4 total findings • Code4rena • ayeslick

#14

high

Call to declareInsolvent() would revert when contract status reaches liquidation point after repayment of credit position 1

medium

Variable balance ERC20 support

medium

Borrower/Lender excessive ETH not refunded and permanently locked in protocol

medium

Lender can reject closing a position

Oct '22

Illuminate

Illuminate

425.10 USDC • 1 total finding • Sherlock • ayeslick

#17

high

An Operator can mint tokens for free

3xcalibur contest

3xcalibur contest

509.15 USDC • Code4rena • ayeslick

#15

Sep '22

Frax Ether Liquid Staking contest

Frax Ether Liquid Staking contest

630.32 USDC • 2 total findings • Code4rena • ayeslick

#10

medium

Centralization risk: admin have privileges: admin can set address to mint any amount of frxETH, can set any address as validator, and change important state in frxETHMinter and withdraw fund from frcETHMinter

medium

Withheld ETH shoud not be sent back to the frxETHMinter contract itself

VTVL contest

VTVL contest

567.72 USDC • 1 total finding • Code4rena • ayeslick

#11

medium

Vesting Schedule Start and End Time can be Set in The Past

PartyDAO contest

PartyDAO contest

141.35 USDC • Code4rena • ayeslick

#28

Nouns Builder contest

Nouns Builder contest

962.07 USDC • 3 total findings • Code4rena • ayeslick

#22

medium

Proposals can be bricked and Auctions stalled by bad settings

medium

Loss of Veto Power can Lead to 51% Attack

medium

Compromised or malicious vetoer can veto any proposals with unrestricted power

Aug '22

FIAT DAO veFDT contest

FIAT DAO veFDT contest

389.99 USDC • 1 total finding • Code4rena • ayeslick

#17

medium

Attacker contract can avoid being blocked by BlockList.sol

Fraxlend (Frax Finance) contest

Fraxlend (Frax Finance) contest

45.85 USDC • Code4rena • ayeslick

#62

Mimo August 2022 contest

Mimo August 2022 contest

4,672.77 USDC • 3 total findings • Code4rena • ayeslick

bronze

high

Automation / management can be set for not yet existing vault

medium

Malicious targets can manipulate MIMOProxy permissions

medium

Vault rebalancing can be exploited if two vaults rebalance into the same vault

Rigor Protocol contest

Rigor Protocol contest

40.62 USDC • Code4rena • ayeslick

#68

Jul '22

Fractional v2 contest

Fractional v2 contest

334.61 USDC • 2 total findings • Code4rena • ayeslick

#37

high

Malicious Users Can Exploit Residual Allowance To Steal Assets

medium

Delegate call in `Vault#_execute` can alter Vault's ownership

Jun '22

Notional x Index Coop

Notional x Index Coop

88.14 USDC • Code4rena • ayeslick

#40