https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

copperscrewer

Security Researcher

Contact Me

High

11

Total

Medium

17

Total

$1.79K

Total Earnings

#1060 All Time

18x

Payouts

regular

1x

Top 10

regular

6x

Top 25

regular

10x

Top 50

All

Sherlock

Code4rena

Immunefi

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

8.90 USDC • 2 total findings • Sherlock • copperscrewer

#16

medium

Incorrect check will DOS adding liquidity for balancer pool from locked SYMM amounts

medium

Rewards distribution duration can be doubled and rate almost halved because of constant reset duration attack

Jan '25

Plaza Finance

Plaza Finance

41.37 USDC • 4 total findings • Sherlock • copperscrewer

#55

high

Minting bond tokens during the Auction will not leave enough coupon tokens for every user to claim

medium

Blacklisted addresses can DOS the auction

medium

Auction can be failed repeatedly reliably by an Attacker by bidding high reserve amount

medium

Auction pool sale limit fails to consider the amount of fees owed

Dec '24

SecondSwap

SecondSwap

0.86 USDC • 3 total findings • Code4rena • c0pp3rscr3w3r

#62

high

Users can claim more that their actual allotment

medium

Incorrect referral fee calculations

medium

Listing potential can not be purchased with discounted price

Lambo.win

Lambo.win

0.3 USDC • 2 total findings • Code4rena • c0pp3rscr3w3r

#35

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

medium

Since the cost of launching a new pool is minimal, an attacker can maliciously consume VirtualTokens.

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

55.83 USDC • 1 total finding • Sherlock • copperscrewer

#30

medium

User loses more deposit value because of incorrect fee calculation

Debita Finance V3

Debita Finance V3

124.13 USDC • 2 total findings • Sherlock • copperscrewer

#24

medium

Attacker will de-list entries to borrowOrders factory

medium

Attacker will de-list lend offers in LendOfferFactory

Jul '24

Karak Restaking

Karak Restaking

0 USDC • Code4rena • c0pp3rscr3w3r

#16

May '24

Olas

Olas

232.44 USDC • 2 total findings • Code4rena • c0pp3rscr3w3r

#12

high

Bonds created in year cross epoch's can lead to lost payouts

medium

Incorrect Handling of Last Nominee Removal in `removeNominee` Function

Munchables

Munchables

0.01 USDC • 1 total finding • Code4rena • c0pp3rscr3w3r

#16

high

Invalid validation allows users to unlock early

Apr '24

Audit Comp | Alchemix

Audit Comp | Alchemix

228 USDC • 2 total findings • Immunefi • copperscrewer

#41

medium

Finding not yet public.

medium

Finding not yet public.

DYAD

DYAD

0.02 USDC • 1 total finding • Code4rena • c0pp3rscr3w3r

#114

high

Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral

Feb '24

AI Arena

AI Arena

7.39 USDC • 2 total findings • Code4rena • c0pp3rscr3w3r

#130

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

medium

Minter / Staker / Spender roles can never be revoked`..,

Jan '24

Salty.IO

Salty.IO

0.78 USDC • 1 total finding • Code4rena • c0pp3rscr3w3r

#117

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

Curves

Curves

0.41 USDC • 2 total findings • Code4rena • c0pp3rscr3w3r

#133

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

Dec '23

Olas

Olas

830.39 USDC • 2 total findings • Code4rena • c0pp3rscr3w3r

#6

high

Bonds created in year cross epoch's can lead to lost payouts

medium

Incorrect Handling of Last Nominee Removal in `removeNominee` Function

Nov '23

Audit Comp | DeGate

Audit Comp | DeGate

250 USDC • 2 total findings • Immunefi • copperscrewer

#30

low

Finding not yet public.

low

Finding not yet public.

Oct '23

NextGen

NextGen

0 USDC • 1 total finding • Code4rena • c0pp3rscr3w3r

#115

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

11.47 USDC • Code4rena • c0pp3rscr3w3r

#60