https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/289d3c0f-b669-4aa2-9900-a1f80f42c91d.jpg

erebus

Security Researcher

Contact Me

High

4

Total

Medium

9

Total

$34.83K

Total Earnings

#291 All Time

14x

Payouts

bronze

1x

3rd Places

regular

4x

Top 10

regular

7x

Top 25

All

Code4rena

Mar '24

zkSync Era

zkSync Era

565.16 USDC • 1 total finding • Code4rena • erebus

#11

medium

Freezed Chain will never be unfreeze since `StateTransitionManager::unfreezeChain` is calling `freezeDiamond` instead of `unfreezeDiamond`.

Feb '24

HydraDX

HydraDX

152.74 USDC • 1 total finding • Code4rena • erebus

#14

medium

[M09] No slippage check in `remove_liquidity` function in omnipool can lead to slippage losses during liquidity withdrawal.

Jan '24

Curves

Curves

15.39 USDC • 2 total findings • Code4rena • erebus

#79

high

Unauthorized Access to setCurves Function

medium

If a user sets their curve token symbol as the default one plus the next token counter instance it will render the whole default naming functionality obsolete

Dec '23

Olas

Olas

4,185.05 USDC • 3 total findings • Code4rena • erebus

bronze

high

Withdrawals can be frozen by creating null deposits

medium

Missing slippage protection in `liquidity_lockbox::withdraw`

medium

Withdraw amount returned by `getLiquidityAmountsAndPositions` may be incorrect

Nov '23

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

4.08 USDC • Code4rena • erebus

#29

Oct '23

Ethena Labs

Ethena Labs

4.52 USDC • Code4rena • erebus

#39

zkSync Era

zkSync Era

25,342.89 USDC • Code4rena • erebus

#5

Aug '23

Dopex

Dopex

65.42 USDC • 1 total finding • Code4rena • erebus

#88

medium

A malicious early depositor can manipulate the `LP-Token` price per share to take an unfair share of future user deposits

veRWA

veRWA

9.82 USDC • Code4rena • erebus

#52

Jul '23

Amphora Protocol

Amphora Protocol

122.45 USDC • 1 total finding • Code4rena • erebus

#17

high

Rounding error in `WUSDA` can result in loss of user funds, especially when manipulated by an attacker

PoolTogether

PoolTogether

15.92 USDC • Code4rena • erebus

#66

Tapioca DAO

Tapioca DAO

1,149.67 USDC • 2 total findings • Code4rena • erebus

#42

high

Tokens can be stolen from other users who have approved Magnetar

medium

Executing transfers before reverting (AKA bad execution flow/logic design)

Basin

Basin

2,177.78 USDC • 1 total finding • Code4rena • erebus

#4

medium

QA Report

Jun '23

Canto

Canto

1,016.48 USDC • 1 total finding • Code4rena • erebus

#7

medium

Potential risk of using `swappedAmount` in case of swap error