Security Researcher
Independent security researcher, 10+ years of experience in software development
High
Total
Medium
Total
Total Earnings
#194 All Time
Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
CodeHawks
Mar '25
Dec '24
high
Fee Evasion via LP Token Transfer Resets Deposit Value
medium
quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.
medium
“Uplift Fee” Incorrectly Falls Back to Minimum Fee Due to Integer Division
medium
Incorrect implementation of QuantammMathGuard.sol#_clampWeights.
low
Inconsistent timestamp storage when the LPNFT is transferred.
Nov '24
Findings not publicly available for private contests.
Sep '24
high
Revert of SignerValidator.validate() caused by bug in IncentiveBits.setOrThrow()
high
clawback() can't be executed because the owner is always BoostCore
medium
Fee on transfer tokens break some of the contracts
medium
The boost's owner can steal the protocol's profit using referralFee = 100%.
medium
block.prevdao is not secure source of randomness and could be manipulated
medium
Issue with rebasing tokens in ERC20Incentive
Aug '24
high
Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function
high
Native token withdrawal fails until manually approved
high
`DeliveryPlace::settleAskTaker` Has Incorrect Access Control
high
Formulaic Error Rounds Down Causing Total Loss Of Funds For Bid Takers During Abort
Jul '24
Jun '24
Findings not publicly available for private contests.
May '24
medium
Insufficient input validation on `SablierV2NFTDescriptor::safeAssetSymbol` allows an attacker to obtain stored XSS
medium
`SablierV2Lockup.sol` - The caller of withdraw and renounce can skip callbacks, by sending less gas
low
Cancelling a Merkle Lockup is only callable by `initialAdmin` even after `admin` had been modified
Apr '24
Findings not publicly available for private contests.
Mar '24
Feb '24
Jan '24
Dec '23
Nov '23
Oct '23
Sep '23
Aug '23