https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_8.png

bytes032

Security Researcher

Contact Me

High

9

Total

Medium

17

Total

$7.69K

Total Earnings

#633 All Time

11x

Payouts

regular

3x

Top 10

regular

7x

Top 25

regular

9x

Top 50

All

Sherlock

Code4rena

Jun '23

Lybra Finance

Lybra Finance

674.67 USDC • 5 total findings • Code4rena • bytes032

#15

high

`_voteSucceeded()` returns true when `againstVotes > forVotes` and vice versa

medium

Due to inappropriately short `votingPeriod` and `votingDelay`, it is near impossible for the governance to function correctly.

medium

Incorrect function call in LybraRETHVault's getAssetPrice

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called

medium

The EUSDMiningIncentives contract is incorrectly implemented and can allow for more than the intended amount of rewards to be minted

May '23

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

201.79 USDC • Code4rena • bytes032

#40

Ajna Protocol

Ajna Protocol

943.84 USDC • 4 total findings • Code4rena • bytes032

#10

high

Claiming accumulated rewards while the contract is underfunded can lead to a loss of rewards

medium

The voting thresholds in Ajna's Extraordinary Funding Mechanism can be manipulated to execute proposals below the expected threshold.

medium

Potential unfair distribution of Rewards due to MEV in updateBucketExchangeRatesAndClaim

medium

It is possible to steal the unallocated part of every delegation period budget

Apr '23

EigenLayer Contest

EigenLayer Contest

1,063.04 USDC • 1 total finding • Code4rena • bytes032

#17

medium

A malicious strategy can permanently DoS all currently pending withdrawals that contain it

Rubicon v2

Rubicon v2

765.99 USDC • 7 total findings • Code4rena • bytes032

#16

high

Reward accounting is incorrect in BathBuddy contract

medium

BathBuddy contract should implement methods to pause and unpause contract

medium

Incorrect fee handling in Position.sol's Market Buy/Sell functions

medium

Zero reward rate calculation impedes low-decimals token distributions

medium

Potential infinite loop in `_borrowLimit` function

medium

The return value of buyAllAmount is incorrect

medium

Incorrect reward duration extension in notifyRewardAmount function

Mar '23

Gitcoin

Gitcoin

78.85 USDC • Sherlock • bytes032

#40

Asymmetry contest

Asymmetry contest

70.84 USDC • 4 total findings • Code4rena • bytes032

#65

high

An attacker can manipulate the preDepositvePrice to steal from other users.

high

Staking, unstaking and rebalanceToWeight can be sandwiched (Mainly rETH deposit )

high

Users can fail to unstake and lose their deserved ETH because malfunctioning or untrusted derivative cannot be removed

medium

DoS due to external call failure

Polynomial Protocol contest

Polynomial Protocol contest

3,679.98 USDC • Code4rena • bytes032

#6

Taurus

Taurus

203.90 USDC • 2 total findings • Sherlock • bytes032

#9

high

Vault will be practically unuseable if collateral token decimals != 18

medium

Vaults can mint unlimit amount of tokens

Feb '23

Surge

Surge

10.60 USDC • 2 total findings • Sherlock • bytes032

#20

high

Malicious depositor can inflate the shares and steal money from other lenders.

medium

Possible race condition when using the approve functionality

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

0.75 USDC • 1 total finding • Code4rena • bytes032

#85

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`