https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

carrot

Security Researcher

Contact Me

High

17

Total

Medium

8

Total

$6.13K

Total Earnings

#689 All Time

14x

Payouts

silver

1x

2nd Places

regular

6x

Top 10

regular

10x

Top 25

All

Sherlock

Mar '23

Olympus Update

Olympus Update

310.09 USDC • 1 total finding • Sherlock • carrot

#4

high

Withdrawals can be halted for all users with external staking

Y2K

Y2K

343.69 USDC • 3 total findings • Sherlock • carrot

#37

high

Users lose premium gained when enrolled to `mintRollovers`

medium

Emissions sent to empty vault is forever locked

medium

Freshness of pricefeed not checked properly

Feb '23

Surge

Surge

3.65 USDC • 1 total finding • Sherlock • carrot

#22

high

Initial user can skew vault ratios to steal funds from later users

Hats

Hats

407.12 USDC • 3 total findings • Sherlock • carrot

#11

high

Incorrect threshold update in `reconcileSignerCount`

medium

Hats can be overwritten

medium

Contract breaks if `targetThreshold` is ever reduced

Syndr

Syndr

1,564.56 USDC • Sherlock • carrot

#5

Findings not publicly available for private contests.

OlympusDAO

OlympusDAO

276.69 USDC • 2 total findings • Sherlock • carrot

#22

high

Decimal error in reward debt handling

high

Incorrect caching of rewards by the `withdraw` function

Volta

Volta

940.93 USDC • Sherlock • carrot

#5

Findings not publicly available for private contests.

Fair Funding by Alchemix & Unstoppable

Fair Funding by Alchemix & Unstoppable

34.48 USDC • 1 total finding • Sherlock • carrot

#8

medium

Starting timestamp can be bypassed by calling `settle`

Carapace

Carapace

18.81 USDC • 1 total finding • Sherlock • carrot

#34

high

Users can skip withdrawal timelocks by spamming requestWithdrawal every cycle

Blueberry

Blueberry

1,304.75 USDC • 4 total findings • Sherlock • carrot

#10

high

IchiLP token pricing mechanism vulnerable to price manipulation

high

Interest earned through lending is forever locked in bank contract

high

Miscalculation of farmed ICHI rewards

high

`reducePosition` in IchiVaultSpell checks max LTV against stale debt values

OpenQ

OpenQ

66.95 USDC • 3 total findings • Sherlock • carrot

#36

high

Bounties can be broken by funding them with malicious ERC20 tokens

high

Refunds can be bricked by triggering OOG (out of gas) in DepositManager

medium

Issuer can be frontrun with spam tokens to brick bounties

Jan '23

UXD Protocol

UXD Protocol

40.93 USDC • 1 total finding • Sherlock • carrot

#27

high

Approval in PerpDeposit.sol can be exploited to cause loss of funds

Nov '22

Bull v Bear

Bull v Bear

746.62 USDC • 4 total findings • Sherlock • carrot

silver

high

Orders can be matched multiple time costing multiple premiums

high

Re-entrancy in certain functions

high

Missing order validation in reclaimContract function

medium

Allow changing of recipient for withdrawToken

Aug '22

Sentiment

Sentiment

70.70 USDC • 1 total finding • Sherlock • carrot

#25

medium

Non Liquidatable Accounts