https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

banditx0x

Security Researcher

Contact Me

High

13

Total

Medium

13

Total

$22.31K

Total Earnings

#333 All Time

16x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

6x

Top 10

All

Sherlock

Code4rena

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • Banditx0x

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

IQ AI

IQ AI

243.25 USDC • 1 total finding • Code4rena • Banditx0x

#13

high

Adversary can win proposals with voting power as low as 4%

Jul '24

MakerDAO Endgame

MakerDAO Endgame

499.05 USDC • Sherlock • banditx0x

#72

Jan '24

Salty.IO

Salty.IO

2,252.86 USDC • 8 total findings • Code4rena • Banditx0x

#5

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

high

The use of spot price by CoreSaltyFeed can lead to price manipulation and undesired liquidations

medium

THE USER WHO WITHDRAWS LIQUIDITY FROM A PARTICULAR POOL IS ABLE TO CLAIM MORE REWARDS THAN HE DULY DESERVES BY CAREFULLY SELECTING A `decreaseShareAmount` VALUE SUCH THAT THE `virtualRewardsToRemove` IS ROUNDED DOWN TO ZERO

medium

MinShares Slippage Parameters Are Ineffective For Initial Deposit

medium

Attacker Can Inflate LP Position Value To Create a Bad Debt Loan

medium

formPOL lacks slippage and deadline protection

medium

StakingRewards pools are not given their promised share of rewards due to incorrect calculation

medium

Minimium Collateral Check Can Be Bypassed

Nov '23

Panoptic

Panoptic

11.32 USDC • Code4rena • Banditx0x

#28

Kelp DAO | rsETH

Kelp DAO | rsETH

4.66 USDC • 1 total finding • Code4rena • Banditx0x

#53

high

The price of rsEHT could be manipulated by the first staker

Oct '23

Canto Liquidity Mining Protocol

Canto Liquidity Mining Protocol

1,112.65 USDC • 2 total findings • Code4rena • Banditx0x

#4

high

Array Length of `tickTracking_ ` Can be Purposely Increased to Brick Minting and Burning of Most Users' Liquidity Positions

medium

Positions that are not eligible for rewards will affect the reward income of eligible positions.

Sep '23

Delegate

Delegate

216.92 USDC • Code4rena • Banditx0x

#8

Aug '23

Livepeer Onchain Treasury Upgrade

Livepeer Onchain Treasury Upgrade

16,701.04 USDC • 1 total finding • Code4rena • Banditx0x

gold

high

By delegating to a non-transcoder, a delegator can reduce the tally of somebody else's vote choice without first granting them any voting power

Cooler Update

Cooler Update

216.31 USDC • 4 total findings • Sherlock • banditx0x

#8

high

Malicious lender can use Callbacks to create Loan that cannot be repaid

high

Lender Loses Collateral from Paritailly Repaid Loans that are Defaulted if repayDirect == true

medium

When borrower rolls their loan the lender can frontrun the transaction and change the interest and duration to drain all of borrower's approved tokens

medium

RollLoan can be called on someone else's loan giving them worse conditions or defaulting them in 1 block

Apr '23

Rubicon v2

Rubicon v2

15.3 USDC • 4 total findings • Code4rena • Banditx0x

#99

high

Reward accounting is incorrect in BathBuddy contract

high

An attacker can steal all tokens of users that use `FeeWrapper`

medium

Zero reward rate calculation impedes low-decimals token distributions

medium

Calling `ExpiringMarket.stop` and `ExpiringMarket.isClosed` functions cannot pause any functionlities of the market

Mar '23

Gitcoin

Gitcoin

112.19 USDC • Sherlock • banditx0x

#30

Telcoin Update

Telcoin Update

442.29 USDC • 1 total finding • Sherlock • banditx0x

bronze

medium

Users Can Bypass the Delayed Withdrawal

Feb '23

Surge

Surge

3.65 USDC • 1 total finding • Sherlock • banditx0x

#22

high

First Depositor Can Break Minting of Shares

Blueberry

Blueberry

431.08 USDC • 1 total finding • Sherlock • banditx0x

#25

high

Users That Deposit Into Ichi Spell Can be Unfairly Liquidated by Attacker

Jan '23

Cooler

Cooler

47.73 USDC • 1 total finding • Sherlock • banditx0x

#28

high

Permanent freezing of funds: Roll can be called infinite times without extra payment, extending the loan duration to infinity.