https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

danb

Security Researcher

Contact Me

High

20

Total

Medium

28

Total

$64.31K

Total Earnings

#152 All Time

32x

Payouts

silver

1x

2nd Places

bronze

4x

3rd Places

regular

13x

Top 10

All

Code4rena

Jan '24

Curves

Curves

5.2 USDC • 2 total findings • Code4rena • danb

#99

high

Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale

high

Unauthorized Access to setCurves Function

Oct '23

ENS

ENS

8.19 USDC • Code4rena • danb

#19

Aug '22

Foundation Drop contest

Foundation Drop contest

41.26 USDC • Code4rena • danb

#57

Jun '22

Putty contest

Putty contest

810.11 USDC • 2 total findings • Code4rena • danb

#22

high

Create a short call order with non empty floor makes the option impossible to exercise and withdraw

medium

`fillOrder()` and `exercise()` may lock Ether sent to the contract, forever

May '22

FactoryDAO contest

FactoryDAO contest

1,842.62 DAI • 3 total findings • Code4rena • danb

#7

high

SpeedBumpPriceGate: Excess ether did not return to the user

medium

safeTransferFrom is recommended instead of transfer (1)

medium

wrong out of range check

Cudos contest

Cudos contest

1,237.09 USDC • 2 total findings • Code4rena • danb

#13

medium

Missing check in the updateValset function

medium

Admin drains all ERC based user funds using withdrawERC20()

Apr '22

Backd contest

Backd contest

70.08 USDC • 1 total finding • Code4rena • danb

#42

medium

`call()` should be used instead of `transfer()` on an `address payable`

Badger Citadel contest

Badger Citadel contest

3,956.28 USDC • 3 total findings • Code4rena • danb

#7

high

StakedCitadel depositors can be attacked by the first depositor with depressing of vault token denomination

high

StakedCitadel doesn't use correct balance for internal accounting

medium

Funding.deposit() doesn't work if there is no discount set

Backed Protocol contest

Backed Protocol contest

293.89 USDC • 1 total finding • Code4rena • danb

#17

high

Can force borrower to pay huge interest

Mar '22

Volt Protocol contest

Volt Protocol contest

125.78 USDC • Code4rena • danb

#26

Paladin contest

Paladin contest

934.14 USDC • 1 total finding • Code4rena • danb

#11

medium

Add a timelock to PaladinRewardReserve functions

LI.FI contest

LI.FI contest

1,121.31 USDC • 2 total findings • Code4rena • danb

#19

medium

ERC20 bridging functions do not revert on non-zero msg.value

medium

Reputation Risks with `contractOwner`

Rolla contest

Rolla contest

947.65 USDC • 1 total finding • Code4rena • danb

#9

medium

COLLATERAL_MINTER_ROLE can be granted by the deployer of QuantConfig and mint arbitrary amount of tokens

Biconomy Hyphen 2.0 contest

Biconomy Hyphen 2.0 contest

860.62 USDT • 3 total findings • Code4rena • danb

#15

medium

DoS by gas limit

medium

Improper Upper Bound Definition on the Fee

medium

Owners have absolute control over protocol

Feb '22

Hubble contest

Hubble contest

5,902.17 USDC • 3 total findings • Code4rena • danb

#6

high

denial fo service

high

InsuranceFund depositors can be priced out & deposits can be stolen

medium

liquidation is vulnerable to sandwich attacks

Redacted Cartel contest

Redacted Cartel contest

1,031.89 USDC • 3 total findings • Code4rena • danb

#9

medium

Wrong slippage check

medium

fees can be any amount

medium

[WP-H0] `DEFAULT_ADMIN_ROLE` of `BribeVault` can steal tokens from users' wallets

Aave Lens contest

Aave Lens contest

13,481.36 USDC • 2 total findings • Code4rena • danb

bronze

medium

It's possible to follow deleted profiles

medium

missing whenNotPaused

Concur Finance contest

Concur Finance contest

484.53 USDC • 3 total findings • Code4rena • danb

#24

high

[WP-H14] `ConvexStakingWrapper`, `StakingRewards` Wrong implementation will send `concur` rewards to the wrong receiver

high

Repeated Calls to Shelter.withdraw Can Drain All Funds in Shelter

medium

[WP-H2] `ConvexStakingWrapper#deposit()` depositors may lose their funds when the `_amount` is huge

Jan '22

Behodler contest

Behodler contest

8,012.73 USDC • 2 total findings • Code4rena • danb

bronze

high

wrong minting amount

high

Double transfer in the `transferAndCall` function of `ERC677`

Sherlock contest

Sherlock contest

2,434.92 USDC • Code4rena • danb

#10

ElasticSwap contest

ElasticSwap contest

1,250.6 USDC • 1 total finding • Code4rena • danb

#5

medium

[WP-H1] The value of LP token can be manipulated by the first minister, which allows the attacker to dilute future liquidity providers' shares

Livepeer contest

Livepeer contest

919.3 tokens) • Code4rena • danb

#11

InsureDAO contest

InsureDAO contest

5,356.01 tokens) • 3 total findings • Code4rena • danb

bronze

high

the first depositor to a pool can drain all users

high

[WP-H39] `PoolTemplate.sol#resume()` Wrong implementation of `resume()` will compensate overmuch redeem amount from index pools

medium

Unbounded iteration over all indexes (2)

Sandclock contest

Sandclock contest

1,561.5 USDC • 5 total findings • Code4rena • danb

#13

high

deposit() function is open to reentrancy attacks

high

Vaults with non-UST underlying asset vulnerable to flash loan attack on curve pool

medium

`investedAssets()` Does Not Take Into Consideration The Performance Fee Charged On Strategy Withdrawals

medium

unsponsor, claimYield and withdraw might fail unexpectadly

medium

Changing a strategy can be bricked

XDEFI contest

XDEFI contest

30.27 USDC • Code4rena • danb

#29

Timeswap contest

Timeswap contest

2,145.59 USDC • 1 total finding • Code4rena • danb

#5

medium

users might pay enormous amouts of gas

Dec '21

Vader Protocol contest

Vader Protocol contest

2,561.7 USDC • 3 total findings • Code4rena • danb

bronze

high

`VaderPoolV2` minting synths & fungibles can be frontrun

high

Oracle doesn't calculate USDV/VADER price correctly

high

denial of service

PoolTogether TwabRewards contest

PoolTogether TwabRewards contest

4.78 USDC • Code4rena • danb

#25

Kuiper contest

Kuiper contest

16.43 ETH • Code4rena • danb

#16

Nov '21

Streaming Protocol contest

Streaming Protocol contest

7.61 USDC • Code4rena • danb

#35

Fei Protocol contest

Fei Protocol contest

6,557.61 USDC • Code4rena • danb

silver
Malt Finance contest

Malt Finance contest

298.01 USDC • 1 total finding • Code4rena • danb

#25

medium

theft of system profit