https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

crypticdefense

Security Researcher

Contact Me

High

19

Total

Medium

23

Total

$43.01K

Total Earnings

#223 All Time

16x

Payouts

gold

1x

1st Places

regular

1x

Top 10

regular

7x

Top 25

All

Code4rena

Cantina

CodeHawks

May '25

mystic-monorepo

mystic-monorepo

124.26 USDC • 8 total findings • Cantina • crypticdefense

#26

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Aquarius

Aquarius

224.38 USDC • 1 total finding • Cantina • crypticdefense

#37

medium

Finding not yet public.

Jan '25

infrared-contracts

infrared-contracts

92.62 USDC • 1 total finding • Cantina • crypticdefense

#55

high

Finding not yet public.

Oct '24

balancer-v3

balancer-v3

37,700.83 USDC • 1 total finding • Cantina • crypticdefense

gold

medium

Finding not yet public.

Sep '24

uniswap-v4

uniswap-v4

625 USDC • Cantina • crypticdefense

#34

Aug '24

zetachain-protocol

zetachain-protocol

1,153.16 USDC • 7 total findings • Cantina • crypticdefense

#23

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

LoopFi

LoopFi

1,514.15 USDC • 6 total findings • Code4rena • crypticdefense

#12

high

Liquidation doesn't account for penalty when calculating collateral to give, allowing users to profit by borrowing and self-liquidating

high

`AuraVault::claim` reward calculation does not deduct fees from reward amount, causing DoS or extra rewards lost

high

`Flashlender.sol#flashLoan()` should use `mintProfit()` to mint fees. The current implemetation may lead to locked up WETH in PoolV3.

medium

In CDPVault::liquidatePositionBadDebt(), the calculation of `loss` is incorrect.

medium

Lack of Slippage Control in `AuraVault::deposit` and `AuraVault::mint` Functions Can Lead to Unexpected Financial Losses for Users

medium

`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`

Jun '24

Vultisig

Vultisig

404.29 USDC • 2 total findings • Code4rena • crypticdefense

#11

high

Most users won't be able to claim their share of Uniswap fees

medium

`claim` function lacks slippage controls for `amount0` and `amount1` returned by `pool.burn` function call

May '24

Predy

Predy

497.1 USDC • 2 total findings • Code4rena • crypticdefense

#16

medium

Liquidity manipulation is possible when trading

medium

Possible DoS When calling `GammaTradeMarket::_removePosition` will cause user position to not be able to get liquidated

Munchables

Munchables

0.02 USDC • 3 total findings • Code4rena • crypticdefense

#15

high

Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens

high

Invalid validation allows users to unlock early

medium

Missing disapproval check in `LockManager.sol::approveUSDPrice` allows simultaneous approval and disapproval of a price proposal

safe-extensions

safe-extensions

87.5 USDC • 1 total finding • Cantina • crypticdefense

#26

medium

Finding not yet public.

Apr '24

Renzo

Renzo

259.2 USDC • 4 total findings • Code4rena • crypticdefense

#29

high

Incorrect withdraw queue balance in TVL calculation

high

Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps

high

DOS of `completeQueuedWithdrawal` when ERC20 buffer is filled

medium

Lack of slippage and deadline during withdraw and deposit

Mar '24

Revert Lend

Revert Lend

35.4 USDC • 2 total findings • Code4rena • crypticdefense

#60

medium

V3Oracle susceptible to price manipulation

medium

V3Vault is not ERC-4626 compliant

PoolTogether

PoolTogether

1.47 USDC • 1 total finding • Code4rena • crypticdefense

#29

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

Feb '24

opal-contracts

opal-contracts

281.96 USDC • 3 total findings • Cantina • crypticdefense

#25

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Jan '24

MorpheusAI

MorpheusAI

4.59 USDC • 1 total finding • CodeHawks • crypticdefense

#26

low

LayerZeroEndpoint.send() in L1Sender.sol may revert if the user does not provide enough native gas as specified