https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

crunter

Security Researcher

Contact Me

High

5

Total

Medium

6

Total

$21.36K

Total Earnings

#369 All Time

13x

Payouts

regular

4x

Top 10

regular

10x

Top 25

regular

11x

Top 50

All

Code4rena

CodeHawks

Mar '25

Nudge.xyz

Nudge.xyz

0.06 USDC • 1 total finding • Code4rena • crunter

#8

medium

Unauthorized Reallocation in `NudgeCampaign::handleReallocation` and Reward Disruption Vulnerability in `NudgeCampaign::invalidateParticipations`

StarkWare Perps

StarkWare Perps

8,161.96 USDC • Code4rena • crunter

#4

Feb '25

Core Contracts

Core Contracts

5.97 usdc • 6 total findings • CodeHawks • crunter

#301

high

Users can borrow more assets than they have deposited as collateral

medium

LendingPool deposits do not work with CurveVault due to lack of funds

medium

Missing Liquidity Rebalancing in Repayments and Liquidations Leading to Inefficient Liquidity Management

low

`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types

low

Wrong event emitted in `LendingPool::_repay`

low

`collateralLiquidated` value is always 0 when emitted in the `LiquidationFinalized` event

Jan '25

Aave DIVA Wrapper

Aave DIVA Wrapper

28.54 usdc • 1 total finding • CodeHawks • crunter

#7

low

The Aave pool is hardcoded

Dec '24

QuantAMM

QuantAMM

935.98 op • 3 total findings • CodeHawks • crunter

#14

high

Out-of-Bounds Array Access in `_calculateQuantAMMVariance` with Odd Number of Assets and Vector Lambda

high

Denial of service when calculating the new weights if the rule requires previous moving averages

high

GradientBasedRules will not work for >=4 assets with vector lambdas

Alchemix Transmuter

Alchemix Transmuter

14.98 op • 3 total findings • CodeHawks • crunter

#24

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

low

Missing Router Update Mechanism in StrategyMainnet Contract

low

Old router retains token allowance after update

Oct '24

Era

Era

8,876.14 USDC • CodeHawks • crunter

#11

Sep '24

Staking

Staking

2,299.94 USDC • CodeHawks • crunter

#7

Aug '24

Fjord Token Staking

Fjord Token Staking

0.19 USDC • 1 total finding • CodeHawks • crunter

#20

medium

[H-01] Auction tokens will be lost forever when auction ends without bids

Jul '24

ArkProject: NFT Bridge

ArkProject: NFT Bridge

158.26 USDC • 1 total finding • CodeHawks • crunter

#32

low

function erc721Metadata returns empty base uri instead of token uris

Zaros Part 1

Zaros Part 1

12.16 USDC • 1 total finding • CodeHawks • crunter

#85

low

QA Report - 0xStalin - Low Severities

CCIP v1.5

CCIP v1.5

244.02 USDC • CodeHawks • crunter

#13

May '24

Beanstalk: The Finale

Beanstalk: The Finale

627.61 USDC • 2 total findings • CodeHawks • crunter

#17

high

`LibChainlinkOracle::getTokenPrice` will always return instantaneuous prices

medium

quickSort function does not work as expected, compromising the calculation of Beans per Well to be minted during a flood