Web3 Security Researcher
security, data, AI, and other stuffs.
High
Total
Medium
Total Earnings
#1338 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
CodeHawks
Jul '25
7.11 USDC • 3 total findings • Sherlock • boredpukar
#37
high
Consensus Threshold Bypass via Duplicate Signer Entries
medium
Incorrect Indexing in `DepositQueue.cancelDepositRequest()` Corrupts Fenwick-Tree Accounting
Transfer-Whitelist Logic Inversion in `ShareManager.updateChecks`
6.11 USDC • Sherlock • boredpukar
#87
240.82 USDC • 3 total findings • Sherlock • boredpukar
#24
Missing Slippage Protection in `PendlePT_sUSDe._executeInstantRedemption` Enables Sandwich Attacks
Hard-Coded Mainnet WETH Address Breaks All Non-Mainnet Deployments
Zero-Cooldown Withdrawals in EthenaWithdrawRequestManager Permanently Strand Users’ USDe
May '25
4.93 USDC • 1 total finding • Cantina • boredpukar
#71
Mar '25
344.05 USDC • 1 total finding • Code4rena • boredpukar
#20
Early 72-digit adjustment in sqrt will lead to incorrect result exponent calculation
Feb '25
0.35 USDC • 1 total finding • Code4rena • boredpukar
#8
MergeTgt has no handling if TGT_TO_EXCHANGE is exceeded during the exchange period
0.66 usdc • 1 total finding • CodeHawks • iampukar
#55
low
Incorrect Token Price Validation in KeeperProxy
Dec '24
4.28 USDC • 1 total finding • Code4rena • boredpukar
#54
Creator of one vesting plan can affect vesting plans created by other users.
Nov '24
5.67 USDC • Sherlock • boredpukar
#58
43.12 USDC • 1 total finding • Cantina • boredpukar
#16
Oct '24
13.52 USDC • 1 total finding • CodeHawks • iampukar
#50
BuyerAgent Batch Purchase Failure Due to Asset Transfer or Approval Revocation
Jul '24
203.35 USDC • 1 total finding • Code4rena • boredpukar
#26
Potential Uninitialized `entropySlots` Reading in `getNextEntropy`, Causing 0 Entropy Mint
Mar '24
6.61 USDC • 1 total finding • Code4rena • boredpukar
#70
V3Oracle susceptible to price manipulation
Feb '24
33.27 USDC • 1 total finding • Sherlock • boredpukar
#30
Fixed Amount of Gas Sent in Call May Be Insufficient.
8.81 USDC • Code4rena • boredpukar
#129
Jan '24
0.09 USDC • 1 total finding • Code4rena • boredpukar
#56
Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.
Nov '23
2.76 USDC • Code4rena • boredpukar
Apr '23
22.6 USDC • Code4rena • boredpukar
#66