https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/2478e11a-a3a8-44e4-868d-f39abfbb3c31.jpg

funkornaut

Security Researcher

Here for a long time not a good time

Contact Me

High

3

Total

Medium

12

Total

$81.00

Total Earnings

#1914 All Time

4x

Payouts

regular

1x

Top 50

All

Sherlock

Code4rena

CodeHawks

Feb '25

Core Contracts

Core Contracts

24.94 usdc • 10 total findings • CodeHawks • funkornaut

#233

high

RAACNFT mint function receives funds to address(this) but has no way of withdrawing them

medium

LendingPool deposits do not work with CurveVault due to lack of funds

medium

Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check

medium

Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator

medium

Token Accounting Mismatch Between tick() and mintRewards() in RAACMinter

medium

Inconsistent Scaling in RToken Transfer Functions

medium

Emergency Withdrawal Remains Active After Cancellation

medium

Wrong access control in `RAACToken::setFeeCollector`, `RAACToken::setSwapTaxRate`, `RAACToken::setBurnTaxRate`

medium

`RAACReleaseOrchestrator::emergencyRevoke()` fails to update `categoryUsed`, leading to token lockup and incorrect accounting

low

Emergency Timelock Bypass: No Enforced 1-Day Delay for Emergency Actions

Apr '24

TITLES Publishing Protocol

TITLES Publishing Protocol

5.27 USDC • 3 total findings • Sherlock • funkornaut

#47

high

Mishandled ether in `Editions::mintBatch` allows tokens to be minted for free

medium

Users are not refunded extra eth

medium

`Editions::mintBatch` is broken

Oct '23

NextGen

NextGen

27.09 USDC • 3 total findings • Code4rena • funkornaut

#76

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders

medium

Auction winner can prevent payments via `safeTransferFrom` callback

medium

Auction payout goes to AuctionDemo contract owner, not the token owner

Jul '23

Foundry DeFi Stablecoin CodeHawks Audit Contest

Foundry DeFi Stablecoin CodeHawks Audit Contest

24.52 USDC • 2 total findings • CodeHawks • funkornaut

#60

low

Pragma isn't specified correctly which can lead to nonfunction/damaged contract when deployed on Arbitrum

gas

Misleading NatSpec for redeemCollateral function