https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/e317b051-1d99-46e3-ae71-366350fc8b49.jpg

c7e7eff

Security Researcher

https://t.co/P0dDGCRJ7K https://t.co/Pti4UsavV5 sherlockdefi (c7e7eff)

Contact Me

High

9

Total

Medium

15

Total

$4.99K

Total Earnings

#767 All Time

9x

Payouts

regular

2x

Top 10

regular

2x

Top 25

regular

8x

Top 50

All

Sherlock

Code4rena

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

48.83 USDC • Code4rena • c7e7eff

#54

Jul '23

Tapioca DAO

Tapioca DAO

1,493.17 USDC • 6 total findings • Code4rena • c7e7eff

#34

high

Potential 99.5% loss in `emergencyWithdraw()` of two Yieldbox strategies

high

Attacker can prevent rewards from being issued to gauges for a given epoch in TapiocaOptionBroker

medium

Tapioca Bar: Unusable Market Add Functions in Penrose Contract

medium

all deposit and withdraw function in Convex and Curve nativeLP Strategy, apply slippage on internal pricing; which call real-time on chain price from Curve directly and subject to MEV

medium

The twTAP multiplier can be compromised with manipulated deposits of low value cost and high duration

medium

read-only reentrancy in Curve Eth pool can lead to funds being stolen from the Lido strategy

Feb '23

Derby

Derby

1,421.63 USDC • 7 total findings • Sherlock • c7e7eff

#9

high

Anyone can execute certain functions that use cross chain messages and potentially cancel them with potential loss of funds.

medium

rebalanceXChain() can be called by anyone specifying a extreme high slippage

medium

Derby vault rebalance fails when exchange rate of protocol LP tokens decreases.

medium

Yearn withdrawal can revert making it impossible to rebalance the Derby vault

medium

maxTrainingDeposit can be trivially circumvented

medium

Aave Liquidity Pools do not count towards rewards

medium

DAI, USDT and USDC are assumed to have an 1 to 1 exchange rate in the Curve 3pool

Carapace

Carapace

107.08 USDC • 1 total finding • Sherlock • c7e7eff

#29

high

C7e7eff - Ineffective remaining principal limit for buyer

Jan '23

Astaria contest

Astaria contest

430.48 USDC • 2 total findings • Code4rena • c7e7eff

#30

high

Anyone can wipe complete state of any collateral at any point

high

Improper validations in Clearinghouse. possible to lock collateral NFT in contract.

Nov '22

ParaSpace contest

ParaSpace contest

685.9 USDC • 1 total finding • Code4rena • c7e7eff

#31

high

Anyone can steal CryptoPunk during the deposit flow to WPunkGateway

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

64.3 USDC • 2 total findings • Code4rena • c7e7eff

#49

high

Incorrect accounting in SyndicateRewardsProcessor results in any LP token holder being able to steal other LP tokens holder's ETH from the fees and MEV vault.

high

Giant pools can be drained due to weak vault authenticity check

SIZE contest

SIZE contest

667.31 USDC • 3 total findings • Code4rena • c7e7eff

#7

medium

Seller's ability to decrypt bids before reveal could result in a much higher clearing price than anticpated and make buyers distrust the system

medium

Attacker may DOS auctions using invalid bid parameters

medium

Incompatibility with fee-on-transfer/inflationary/deflationary/rebasing tokens, on both base tokens and quote tokens, with varying impacts

Oct '22

Inverse Finance contest

Inverse Finance contest

70.74 USDC • 2 total findings • Code4rena • c7e7eff

#37

medium

Protocol withdrawals of collateral can be unexpectedly locked if governance sets the `collateralFactorBps` to 0.

medium

Chainlink oracle data feed is not sufficiently validated and can return stale `price`