https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/8e7e846f-687f-4bef-94c6-d0e90618b4a1.png

dontonka

Security Researcher

Web3 tiburon

Contact Me

High

20

Total

Medium

32

Total

$269.35K

Total Earnings

#35 All Time

24x

Payouts

silver

2x

2nd Places

bronze

2x

3rd Places

regular

12x

Top 10

All

Code4rena

Cantina

CodeHawks

Immunefi

Feb '25

Pectra

Pectra

2,000 USDC • Cantina • dontonka

#10

Dec '24

story-protocol

story-protocol

45,206.97 USDC • 6 total findings • Cantina • dontonka

#5

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Oct '24

Omni Network

Omni Network

124,991.29 USDC • 3 total findings • Cantina • dontonka

silver

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

mev-commit

mev-commit

1,001.98 USDC • 4 total findings • Cantina • dontonka

#14

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Aug '24

zetachain-protocol

zetachain-protocol

3,235.01 USDC • 7 total findings • Cantina • dontonka

#10

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

TraitForge

TraitForge

15.83 USDC • 8 total findings • Code4rena • dontonka

#66

high

`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`

high

The maximum number of generations is infinite

high

Number of entities in generation can surpass the 10k number

high

Wrong minting logic based on total token count across generations

medium

Forger Entities can forge more times than intended

medium

Pause and unpause functions are inaccessible

medium

Excess ETH from `forgingFee` can get stuck in `EntityForging` under certain situations

medium

Discrepancy between nfts minted, price of nft when a generation changes & position of `_incrementGeneration()` inside `_mintInternal()` & `_mintNewEntity()`

Munchables

Munchables

404.26 USDC • 4 total findings • Code4rena • dontonka

#11

high

Single plot can be occupied by multiple renters

high

Failure to Update Dirty Flag in transferToUnoccupiedPlot Prevents Reward Accumulation On Valid Plot

high

Invalid validation in _farmPlots function allowing a malicious user repeated farming without locked funds

medium

Users can farm on zero-tax land if the landlord locked tokens before the LandManager deployment

CCIP v1.5

CCIP v1.5

10,057.47 USDC • CodeHawks • dontonka

#8

May '24

Bitcoin Staking Scripts

Bitcoin Staking Scripts

10,754.09 USDC • 3 total findings • Cantina • dontonka

bronze

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Arbitrum BoLD

Arbitrum BoLD

5,993.97 USDC • 1 total finding • Code4rena • dontonka

#9

medium

`BOLDUpgradeAction.sol` will fail to upgrade contracts due to error in the `perform` function

Feb '24

Audit Comp | ZeroLend

Audit Comp | ZeroLend

3,439 USDC • 3 total findings • Immunefi • dontonka

#11

high

Finding not yet public.

medium

Finding not yet public.

low

Finding not yet public.

Audit Comp | Puffer Finance

Audit Comp | Puffer Finance

1,699 USDC • 1 total finding • Immunefi • dontonka

#8

medium

Finding not yet public.

Jan '24

Blast

Blast

43,404.65 USDC • 2 total findings • Cantina • dontonka

#8

high

Finding not yet public.

medium

Finding not yet public.

Nov '23

ZetaChain

ZetaChain

6,998.08 USDC • 7 total findings • Code4rena • dontonka

#6

high

User funds can be lost in favor of Zeta protocol during a CCTX due to contracts being paused

high

Disabling outbound transactions is ineffective and allows for Zeta token theft

medium

Possible index out of range in GetVoterIndex could cause ballot to never finalize due to panic

medium

When updating gas, if one chain fails, the others should continue to be updated instead of being skipped.

medium

UpdateSystemContract is not copying gasPriceByChainId state variable to the new upgraded which will halt ZRC20 token withdraw until system contract is updated accordingly

medium

Outbound zEVM cross-chain messages ignore the user-specified gas limit and may fail with an out-of-gas error

medium

User not refunded for failed Zeta gas payment in cross chain transaction

Audit Comp | DeGate

Audit Comp | DeGate

3,000 USDC • 2 total findings • Immunefi • dontonka

bronze

low

Finding not yet public.

low

Finding not yet public.

Oct '23

zkSync Era

zkSync Era

3,293.31 USDC • Code4rena • dontonka

#21

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

41.45 USDC • Code4rena • dontonka

#57

Sparkn

Sparkn

77.33 USDC • 3 total findings • CodeHawks • dontonka

#31

medium

Blacklisted STADIUM_ADDRESS address cause fund stuck in the contract forever

low

If a winner is blacklisted on any of the tokens they can't receive their funds

low

Using basis points for percentage is not precise enough for realistic use-cases

Jul '23

Tapioca DAO

Tapioca DAO

71.21 USDC • 1 total finding • Code4rena • dontonka

#81

medium

Potential loss of value in YieldBox's `depositETHAsset()`

Jun '23

Canto

Canto

3,562.76 USDC • 1 total finding • Code4rena • dontonka

silver

high

Pre-defined limit is different from the spec.

Stader Labs

Stader Labs

18.57 USDC • Code4rena • dontonka

#36

Apr '23

Rubicon v2

Rubicon v2

0.07 USDC • 1 total finding • Code4rena • dontonka

#126

high

Reward accounting is incorrect in BathBuddy contract

Mar '23

Wenwin contest

Wenwin contest

21.7 USDC • Code4rena • dontonka

#26

Feb '23

Ethos Reserve contest

Ethos Reserve contest

61.26 USDC • Code4rena • dontonka

#33