Banner
https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/f856d461-07c3-4b44-96af-b580357d436e.png

ciphermarco

Web3 Security Researcher / Bug Bounty Hunter ~ Hunting vulnerabilities others miss

Contact Me

High

5

Total

Medium

6

Total

$21.24K

Total Earnings

#424 All Time

6x

Payouts

gold

1x

1st Places

regular

2x

Top 10

regular

3x

Top 25

All

Code4rena

Nov '23

ZetaChain

ZetaChain

8,786.14 USDC • 5 total findings • Code4rena • ciphermarco

#4

high

TSS Key Voting Hash Collision

high

Using unconfirmed UTXOs as inputs for transactions is vulnerable to griefing attacks

high

Broken `NonceVoter` Allows Observer to Halt the Chain

medium

Limited Voting Options Allow Ballot Creation Spam

medium

`AddBlockHeader` Cannot Cope with Reorgs

Oct '23

NextGen

NextGen

0 USDC • 1 total finding • Code4rena • ciphermarco

#111

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

Ethena Labs

Ethena Labs

520.42 USDC • 1 total finding • Code4rena • ciphermarco

#12

medium

Malicious users can front-run to cause a denial of service (DoS) for StakedUSDe due to MinShares checks

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

78.52 USDC • 2 total findings • Code4rena • ciphermarco

#40

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

medium

Incorrect source address decoding in RootBridgeAgent and BranchBridgeAgent's _requiresEndpoint breaks LayerZero communication

Centrifuge

Centrifuge

11,760.71 USDC • 1 total finding • Code4rena • ciphermarco

gold

medium

DelayedAdmin Cannot `PauseAdmin.removePauser`

Aug '23

Dopex

Dopex

90.63 USDC • 1 total finding • Code4rena • ciphermarco

#83

medium

Missing slippage parameter on Uniswap `addLiquidity()` function