Security Researcher
High
Total
Medium
Total Earnings
#360 All Time
Payouts
1st Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Immunefi
Aug '25
941.02 USDC • 1 total finding • Sherlock • c3phas
medium
Users with the FULL_RESTRICTED_STAKER_ROLE can still stake whenever receiver is not restricted
Jul '25
75 USDC • 1 total finding • Immunefi • c3phas
#18
low
May '25
135.95 USDC • 6 total findings • Cantina • c3phas
#23
high
Apr '25
12.18 USDC • 2 total findings • Cantina • c3phas
#69
Mar '25
0.01 USDC • 1 total finding • Sherlock • c3phas
#12
Attacker can steal all tokens as a result of the payWithERC20() function being public
Jan '25
106.11 USDC • 2 total findings • Cantina • c3phas
#38
Dec '24
615.38 USDC • 1 total finding • Sherlock • c3phas
Using Stale price in pyth network
Jan '24
67.43 USDC • 2 total findings • Code4rena • c3phas
#54
Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale
Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.
Oct '23
120.11 USDC • 2 total findings • Code4rena • c3phas
#55
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime
Bidder Funds Can Become Unrecoverable Due to 1 second Overlap in `participateToAuction()` and `claimAuction()`
Jul '23
0.00 USDC • 1 total finding • CodeHawks • c3phas
#233
gas
Uncheck Arithmetic where overflow/underflow impossible
Jan '23
113.94 USDC • 1 total finding • Code4rena • c3phas
Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts
Jul '22
129.23 USDC • 1 total finding • Code4rena • c3phas
#37
transfer() depends on gas consts
174.66 USDC • 1 total finding • Code4rena • c3phas
#51
Use of `payable.transfer()` may lock user funds