https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_8.png

gjaldon

Security Researcher

Contact Me

High

15

Total

Medium

10

Total

$32.99K

Total Earnings

#271 All Time

10x

Payouts

silver

1x

2nd Places

bronze

1x

3rd Places

regular

4x

Top 10

All

Sherlock

Blackthorn

Code4rena

Cantina

Dec '24

GMX Solana

GMX Solana

Collaborative Audit • Blackthorn • gjaldon

Aug '24

Axelar Network

Axelar Network

6,041.26 USDC • 2 total findings • Code4rena • gjaldon

bronze

high

Bridge requests to remote chains where interchain tokens are not deployed can result in DoS attacks

medium

Axelar cross chain token transfers balance tracking logic is completely broken for rebasing tokens and the transfers of these type of tokens can be exploited

Apr '24

Renzo

Renzo

257.72 USDC • 3 total findings • Code4rena • gjaldon

#31

high

Incorrect withdraw queue balance in TVL calculation

high

Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps

high

DOS of `completeQueuedWithdrawal` when ERC20 buffer is filled

Jan '24

Blast

Blast

7,890.7 USDC • 3 total findings • Cantina • gjaldon

#37

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Dec '23

Rain

Rain

Collaborative Audit • Sherlock • gjaldon

Nov '23

GMX-Solana Blackthorn

GMX-Solana Blackthorn

Collaborative Audit • Blackthorn • gjaldon

Aug '23

Dopex

Dopex

482.63 USDC • 5 total findings • Code4rena • gjaldon

#41

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

high

Incorrect precision assumed from RdpxPriceOracle creates multiple issues related to value inflation/deflation

high

Users can get immediate profit when deposit and redeem in `PerpetualAtlanticVaultLP`

medium

reLP() mintokenAAmount the calculations are wrong.

medium

Can not withdraw RDPX if WETH withdrawn is zero

May '23

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

343.12 USDC • Code4rena • gjaldon

#36

Mar '23

Asymmetry contest

Asymmetry contest

94.45 USDC • 1 total finding • Code4rena • gjaldon

#52

high

A temporary issue shows in the staking functionality which leads to the users receiving less minted tokens.

zkSync Era System Contracts contest

zkSync Era System Contracts contest

2,079.11 USDC • Code4rena • gjaldon

#8

Feb '23

Ethos Reserve contest

Ethos Reserve contest

9,417.93 USDC • 2 total findings • Code4rena • gjaldon

#5

high

Rewards will be locked in LQTYStaking Contract

medium

DOS by directly transferring assets to Reaper Vault

Jan '23

Popcorn contest

Popcorn contest

6,380.37 USDC • 8 total findings • Code4rena • gjaldon

silver

high

First vault depositor can steal other's assets

high

Attacker can steal 99% of total balance from any reward token in any Staking contract

high

Attacker can deploys vaults with a malicious Staking contract

high

Staking rewards can be drained

high

Modifier VaultController._verifyCreatorOrOwner does not work as intented

medium

DOS any Staking contract with Arithmetic Overflow

medium

`MultiRewardStaking.changeRewardSpeed()` breaks the distribution

medium

Faulty Escrow config will lock up reward tokens in Staking contract

Cooler

Cooler

0.30 USDC • 1 total finding • Sherlock • gjaldon

#30

high

gjaldon - Cooler owner can get free loans with zero collateral