https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

deepplus

Security Researcher

Contact Me

High

5

Total

Medium

11

Total

$996.00

Total Earnings

#1236 All Time

9x

Payouts

regular

1x

Top 10

regular

2x

Top 25

regular

7x

Top 50

All

Sherlock

Code4rena

Mar '24

Revert Lend

Revert Lend

366.05 USDC • 2 total findings • Code4rena • deepplus

#33

medium

`AutoExit` could receive a reward calculated from the entire position's fund even if `onlyFee` is true in `AutoExit.execute()`.

medium

Users can lend and borrow above allowed limitations

Feb '24

Rio Network

Rio Network

47.93 USDC • 1 total finding • Sherlock • deepplus

#28

medium

Users can request withdrawal without limit since `availableShares` is calculated incorrectly in `requestWithdrawal` function

Jan '24

Flat Money

Flat Money

80.91 USDC • 1 total finding • Sherlock • deepplus

#17

high

In `settleFundingFees` function of `FlatcoinVault` contract, `_globalPositions.marginDepositedTotal` is updated incorrectly.

LooksRare YOLO

LooksRare YOLO

104.78 USDC • 2 total findings • Sherlock • deepplus

#5

high

Players can raise their opportunities to be a winner unfairly by depositing `0 eth` to rounds using `depositETHIntoMultipleRounds` function.

medium

Since `_depositEth` function doesn't check if the maximum number of deposits is reached, the round may wouldn't be drawn when it should be.

Salty.IO

Salty.IO

268.42 USDC • 1 total finding • Code4rena • deepplus

#46

medium

When forming POL the DAO will end up stucked with DAI and USDS tokens that cannot handle.

Curves

Curves

6.73 USDC • 6 total findings • Code4rena • deepplus

#87

high

Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

onBalanceChange causes previously unclaimed rewards to be cleared

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

medium

If a user sets their curve token symbol as the default one plus the next token counter instance it will render the whole default naming functionality obsolete

reNFT

reNFT

1.8 USDC • Code4rena • deepplus

#68

Dec '23

Revolution Protocol

Revolution Protocol

83.85 USDC • 2 total findings • Code4rena • deepplus

#45

medium

`ERC20TokenEmitter::buyToken` function mints more tokens to users than it should do

medium

Since buyToken function has no slippage checking, users can get less tokens than expected when they buy tokens directly

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

36.03 USDC • 1 total finding • Code4rena • deepplus

#46

high

Protocol mints less rsETH on deposit than intended