https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

catchup

Security Researcher

Contact Me

High

4

Total

Medium

15

Total

$21.54K

Total Earnings

#356 All Time

30x

Payouts

regular

4x

Top 10

regular

12x

Top 25

regular

29x

Top 50

All

Code4rena

Oct '22

Inverse Finance contest

Inverse Finance contest

376.98 USDC • 3 total findings • Code4rena • catchup

#25

medium

User can free from liquidation fee if its escrow balance is less than the calculated liquidation fee.

medium

Protocol withdrawals of collateral can be unexpectedly locked if governance sets the `collateralFactorBps` to 0.

medium

Chainlink oracle data feed is not sufficiently validated and can return stale `price`

Holograph contest

Holograph contest

55.67 USDC • Code4rena • catchup

#37

Trader Joe v2 contest

Trader Joe v2 contest

0.01 USDC • Code4rena • catchup

#33

The Graph L2 bridge contest

The Graph L2 bridge contest

1,773.72 USDC • 1 total finding • Code4rena • catchup

#6

medium

Governor can rug pull the escrow

Sep '22

QuickSwap and StellaSwap contest

QuickSwap and StellaSwap contest

87.52 USDC • 1 total finding • Code4rena • catchup

#29

medium

A "FrontRunning attack" can be made to the `initialize` function

Art Gobblers contest

Art Gobblers contest

123.86 USDC • Code4rena • catchup

#19

Aug '22

Nouns DAO contest

Nouns DAO contest

52.11 USDC • Code4rena • catchup

#37

Jun '22

Putty contest

Putty contest

118.54 USDC • 1 total finding • Code4rena • catchup

#43

medium

`fee` can change without the consent of users

Nibbl contest

Nibbl contest

50.13 USDC • Code4rena • catchup

#27

Illuminate contest

Illuminate contest

142.95 USDC • Code4rena • catchup

#45

Canto contest

Canto contest

1,145.02 USDC • 1 total finding • Code4rena • catchup

#22

high

`lending-market/Note.sol` Wrong implementation of access control

Connext Amarok contest

Connext Amarok contest

230.98 USDC • Code4rena • catchup

#36

Notional x Index Coop

Notional x Index Coop

135.76 USDC • Code4rena • catchup

#33

May '22

Backd Tokenomics contest

Backd Tokenomics contest

171.45 USDC • Code4rena • catchup

#27

veToken Finance contest

veToken Finance contest

158.6 USDT • Code4rena • catchup

#41

Velodrome Finance contest

Velodrome Finance contest

151.56 USDC • Code4rena • catchup

#39

Rubicon contest

Rubicon contest

84.77 USDC • 1 total finding • Code4rena • catchup

#60

medium

No cap on fees can result in a DOS in BathToken.withdraw()

Aura Finance contest

Aura Finance contest

5,454.23 USDC • 1 total finding • Code4rena • catchup

#7

medium

massUpdatePools() is susceptible to DoS with block gas limit

Cally contest

Cally contest

110.38 USDC • 2 total findings • Code4rena • catchup

#34

medium

Use safeTransferFrom instead of transferFrom for ERC721 transfers

medium

Owner can modify the feeRate on existing vaults and steal the strike value on exercise

Enso Finance contest

Enso Finance contest

1,635.09 USDT • Code4rena • catchup

#17

Alchemix contest

Alchemix contest

271.81 DAI • Code4rena • catchup

#26

Forgotten Runes Warrior Guild contest

Forgotten Runes Warrior Guild contest

46.91 USDC • Code4rena • catchup

#49

Apr '22

AbraNFT contest

AbraNFT contest

3,826.94 MIM • 3 total findings • Code4rena • catchup

#5

high

The return value `success` of the get function of the INFTOracle interface is not checked

high

Critical Oracle Manipulation Risk by Lender

high

Mistake while checking LTV to lender accepted LTV

Backd contest

Backd contest

359.26 USDC • Code4rena • catchup

#24

xTRIBE contest

xTRIBE contest

279.4 USDC • Code4rena • catchup

#15

JPEG'd contest

JPEG'd contest

252.1 USDC • Code4rena • catchup

#29

Mar '22

Volt Protocol contest

Volt Protocol contest

2,210.9 USDC • 1 total finding • Code4rena • catchup

#5

medium

Setting new buffer does not reduce current buffer to cap

LI.FI contest

LI.FI contest

1,374.6 USDC • 3 total findings • Code4rena • catchup

#13

medium

[WP-H7] Infinite approval to an arbitrary address can be used to steal all the funds from the contract

medium

DexManagerFacet: batchRemoveDex() removes first dex only

medium

Reputation Risks with `contractOwner`

Biconomy Hyphen 2.0 contest

Biconomy Hyphen 2.0 contest

433.63 USDT • 1 total finding • Code4rena • catchup

#26

medium

Improper Upper Bound Definition on the Fee

Feb '22

Tribe Turbo contest

Tribe Turbo contest

420.84 USDC • Code4rena • catchup

#15