https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/0be63ce4-4ec1-4295-8c30-958cefae92c4.jpg

deth

Security Researcher

Smart Contract Auditor/Researcher I help secure the web3 space.

Contact Me

High

1

Solo

11

Total

Medium

15

Total

$13.14K

Total Earnings

#491 All Time

15x

Payouts

silver

1x

2nd Places

bronze

1x

3rd Places

regular

6x

Top 10

All

Sherlock

Code4rena

Hats Finance

Jun '24

Inverter Network

Inverter Network

7,500 UMA • Hats • deth

bronze

Feb '24

Jala Swap

Jala Swap

618.45 USDC • 2 total findings • Sherlock • deth

#4

medium

JalaRouter02.sol

medium

JalaPair.sol#_update()

Tokemak

Tokemak

180 USDC • 1 total finding • Hats • deth

#12

high

LMPStrategy.sol#getRebalanceVaueStats() - Assumes that LMPVault token decimals are 18, which leads to incorrect accounting

Rio Network

Rio Network

38.85 USDC • 2 total findings • Sherlock • deth

#29

high

RioLRTWithdrawalQueue.sol#settleEpochFromEigenLayer()

medium

Asset.sol#transferETH()

Jan '24

Arcadia

Arcadia

36.24 USDC • 1 total finding • Sherlock • deth

#8

medium

AbstractStakingAM.sol#_getRewardBalances()

Decent

Decent

955.55 USDC • 4 total findings • Code4rena • deth

#8

high

When `DecentBridgeExecutor.execute` fails, funds will be sent to a random address

high

Users will lose their cross-chain transaction if the destination router do not have enough WETH reserves.

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

medium

DecentEthRouter.sol#_bridgeWithPayload() - Any refunded ETH (native token) will be refunded to the DecentBridgeAdapter, making them stuck

Dec '23

Revolution Protocol

Revolution Protocol

113.04 USDC • 4 total findings • Code4rena • deth

#44

medium

The quorumVotes can be bypassed

medium

CultureIndex.sol#dropTopVotedPiece() - Malicious user can manipulate topVotedPiece to DoS the whole CultureIndex and AuctionHouse

medium

Bidder can use donations to get VerbsToken from auction that already ended.

medium

It may be possible to DoS AuctionHouse by specifying malicious creators

Ethereum Credit Guild

Ethereum Credit Guild

85.84 USDC • 1 total finding • Code4rena • deth

#67

medium

Re-triggering the `canOffboard[term]` flag to bypass the DAO vote of the lending term offboarding mechanism

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

983.25 USDC • 3 total findings • Code4rena • deth

#7

high

The price of rsEHT could be manipulated by the first staker

high

Possible arbitrage from Chainlink price discrepancy

medium

Update in strategy will cause wrong issuance of shares

Oct '23

The Wildcat Protocol

The Wildcat Protocol

407.94 USDC • 4 total findings • Code4rena • deth

#22

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

high

Borrower can drain all funds of a sanctioned lender

medium

Function WildcatMarketController.setAnnualInterestBips allows for values outside the factory range

medium

`collectFees()` updates delinquency wrongly as `_writeState()` is called before assets are transferred

Sep '23

Venus Prime

Venus Prime

166.82 USDC • 1 total finding • Code4rena • deth

#23

high

Prime.sol - User can claim Prime token without having any staked XVS, because his `stakedAt` isn't reset whenever he is issued an irrevocable token.

Centrifuge

Centrifuge

50.43 USDC • 1 total finding • Code4rena • deth

#31

medium

```trancheTokenAmount``` should be rounded UP when proceeding to a withdrawal or previewing a withdrawal.

Aug '23

Cooler Update

Cooler Update

1,985.85 USDC • 2 total findings • Sherlock • deth

silver

high

Clearinghouse.sol#claimDefaulted()

medium

Cooler.sol#provideNewTermsForRoll()

veRWA

veRWA

9.82 USDC • Code4rena • deth

#52

Jul '23

Amphora Protocol

Amphora Protocol

9.43 USDC • Code4rena • deth

#23