https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/d92adb89-94c2-45e6-82d8-ec188eff0f3f.jpg

degensec

Security Researcher

bounty hunter

Contact Me

High

6

Total

Medium

10

Total

$2.37K

Total Earnings

#1023 All Time

8x

Payouts

regular

2x

Top 25

regular

4x

Top 50

All

Code4rena

CodeHawks

Oct '23

NextGen

NextGen

826.02 USDC • 4 total findings • Code4rena • degensec

#13

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

high

Attacker can reenter to mint all the collection supply

medium

getPrice `salesOption` 2 can round down to the lower barrier, skipping the last time period

medium

Auction payout goes to AuctionDemo contract owner, not the token owner

Ethena Labs

Ethena Labs

123.66 USDC • 1 total finding • Code4rena • degensec

#26

medium

``FULL_RESTRICTED`` Stakers can bypass restriction through approvals

Sep '23

Centrifuge

Centrifuge

533.61 USDC • 1 total finding • Code4rena • degensec

#20

medium

The Restriction Manager does not completely implement ERC1404 which leads to account that are supposed to be restricted actually have access to do with their tokens as they see fit

Aug '23

Dopex

Dopex

67.53 USDC • 4 total findings • Code4rena • degensec

#87

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

high

The peg stability module can be compromised by forcing lowerDepeg to revert.

medium

Inaccurate swap amount calculation in ReLP leads to stuck tokens and lost liquidity

medium

Change of `fundingDuration` causes "time travel" of `PerpetualAtlanticVault.nextFundingPaymentTimestamp()`

Tangible Caviar

Tangible Caviar

6.15 USDC • Code4rena • degensec

#82

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

76.85 USDC • 4 total findings • CodeHawks • degensec

#51

high

Tokens with less than 18 decimals allow for draining of funds

high

Sandwich attack to steal all ERC-20 tokens in the Fees contract

medium

Precision loss allows users to giveLoans to pools with less collateral then required

medium

The `borrow` and `refinance` functions can be front-run by the pool lender to set high interest rates

Foundry DeFi Stablecoin CodeHawks Audit Contest

Foundry DeFi Stablecoin CodeHawks Audit Contest

0.00 USDC • 1 total finding • CodeHawks • degensec

#163

medium

Chainlink oracle will return the wrong price if the aggregator hits `minAnswer`

PoolTogether

PoolTogether

739.79 USDC • 1 total finding • Code4rena • degensec

#26

medium

Vault does not conform to ERC4626