https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

devival

Security Researcher

Contact Me

High

6

Total

Medium

11

Total

$2.15K

Total Earnings

#1064 All Time

9x

Payouts

regular

1x

Top 10

regular

1x

Top 25

regular

5x

Top 50

All

Code4rena

Cantina

CodeHawks

Jan '25

farcasterattestation-monorepo

farcasterattestation-monorepo

53.45 OP • 1 total finding • Cantina • gorgut

#35

high

Finding not yet public.

Aug '24

Chakra

Chakra

45.67 USDT • 4 total findings • Code4rena • devival

#38

high

In Starknet already processed messages can be re-submitted and by anyone

high

Invalid token address used in `ChakraSettlementHandler::cross_chain_erc20_settlement(...)` leading to invalid transaction creation and event emission

medium

Does not check if to_chain and to_handler is whitelisted in cross_chain_erc20_settlement

medium

Excessive Authority Granted to Managers in the `ckr_btc.cairo` Contract Presents Significant Management Risks

Superposition

Superposition

140.91 USDC • 2 total findings • Code4rena • devival

#26

high

Missing `lower<upper` check in `mint_position`

medium

Users can't remove liquidity while a pool is disabled

Oct '23

NextGen

NextGen

38.63 USDC • 2 total findings • Code4rena • devival

#67

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

medium

Auction payout goes to AuctionDemo contract owner, not the token owner

The Wildcat Protocol

The Wildcat Protocol

182.26 USDC • 1 total finding • Code4rena • devival

#36

medium

Protocol markets are incompatible with rebasing tokens

Aug '23

veRWA

veRWA

4.23 USDC • Code4rena • devival

#53

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

4.52 USDC • 1 total finding • CodeHawks • devival

#173

gas

Wrong comment in `setPool` function

Foundry DeFi Stablecoin CodeHawks Audit Contest

Foundry DeFi Stablecoin CodeHawks Audit Contest

1.58 USDC • 4 total findings • CodeHawks • devival

#121

medium

DSC protocol can consume stale price data or cannot operate on some EVM chains

medium

Chainlink oracle will return the wrong price if the aggregator hits `minAnswer`

gas

Double checks

gas

Use `==` instead for `<=` for `uints` when comparing for `zero` values

Jun '23

Lybra Finance

Lybra Finance

1,674.57 USDC • 5 total findings • Code4rena • devival

#7

high

`_voteSucceeded()` returns true when `againstVotes > forVotes` and vice versa

medium

Due to inappropriately short `votingPeriod` and `votingDelay`, it is near impossible for the governance to function correctly.

medium

Incorrect function call in LybraRETHVault's getAssetPrice

medium

Liquidation won't work when bad and safe collateral ratio are set to default values

medium

Wrong `proposalThreshold` amount in `LybraGovernance.sol`