https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

fugazzi

Security Researcher

Contact Me

High

6

Total

Medium

10

Total

$18.29K

Total Earnings

#373 All Time

9x

Payouts

gold

2x

1st Places

silver

1x

2nd Places

bronze

2x

3rd Places

All

Sherlock

Jan '25

Aave v3.3

Aave v3.3

5,369.66 USDC • Sherlock • fugazzi

#11

Apr '24

TITLES Publishing Protocol

TITLES Publishing Protocol

410.41 USDC • 8 total findings • Sherlock • fugazzi

#11

high

`mintBatch()` can be used to skip minting fees

medium

Edition minting is supposed to refund unused fees to caller but forwards all value to FeeManager

medium

`mintBatch()` for multiple token ids is broken

medium

Promo minter role cannot be assigned

medium

Invalid data encoding breaks EIP-712 compatibility

medium

Signatures can be replayed by abusing signature malleability

medium

Edges cannot be acknowledged

medium

TitlesGraph is incorrectly initialized, breaking upgradeability

Mar '24

vVv Vesting & Staking

vVv Vesting & Staking

823.35 USDC • Sherlock • fugazzi

bronze
RadicalxChange

RadicalxChange

1.18 USDC • 1 total finding • Sherlock • fugazzi

bronze

high

Users can cancel the highest bid for the current round

Amphor

Amphor

2,506.89 USDC • 3 total findings • Sherlock • fugazzi

silver

high

Loss of funds when requesting a redeem for a receiver different than the owner

high

Claim functions don't validate if the epoch is settled

high

Functions used to convert between assets and shares for settled epochs are incorrect

Feb '24

Rio Network

Rio Network

1,065.27 USDC • 2 total findings • Sherlock • fugazzi

#12

medium

Missing safe approval in initial deposit could cause a denial of service for USDT-like tokens

medium

Intrinsic arbitrage due to price feed discrepancies could lead to loss of value for the protocol

Jan '24

Avail

Avail

3,617.63 USDC • Sherlock • fugazzi

gold
Rio Vesting Escrow

Rio Vesting Escrow

2,625 USDC • 1 total finding • Sherlock • fugazzi

gold

high

VestingEscrow implementation can be destroyed bricking all deployed instances

Ubiquity

Ubiquity

1,866.60 USDC • 1 total finding • Sherlock • fugazzi

#6

medium

Fragile collateralization model will likely cause bad debt