https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

glcanvas

Security Researcher

Contact Me

High

6

Total

Medium

15

Total

$10.28K

Total Earnings

#568 All Time

15x

Payouts

bronze

1x

3rd Places

regular

3x

Top 10

regular

9x

Top 25

All

Code4rena

Cantina

May '24

Euler-v2

Euler-v2

1,592 USDC • Cantina • glcanvas

#28

Feb '24

curvance

curvance

185.62 USDC • 1 total finding • Cantina • glcanvas

#41

medium

Finding not yet public.

arcadexyz/arcade-protocol

arcadexyz/arcade-protocol

3,013.44 USDC • 1 total finding • Cantina • glcanvas

#5

medium

Finding not yet public.

Nov '23

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

208.48 USDC • 2 total findings • Code4rena • glcanvas

#16

medium

No slippage protection for Market functions

medium

Users will lose rewards when buying new tokens if they already own some tokens

Kelp DAO | rsETH

Kelp DAO | rsETH

155.3 USDC • 1 total finding • Code4rena • glcanvas

#23

medium

Lack of slippage control on LRTDepositPool.depositAsset

Oct '23

NextGen

NextGen

30.46 USDC • 1 total finding • Code4rena • glcanvas

#72

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders

Sep '23

Venus Prime

Venus Prime

4.37 USDC • Code4rena • glcanvas

#39

Aug '23

Dopex

Dopex

1,067.33 USDC • 3 total findings • Code4rena • glcanvas

#17

high

The peg stability module can be compromised by forcing lowerDepeg to revert.

high

Users can get immediate profit when deposit and redeem in `PerpetualAtlanticVaultLP`

medium

The owner of RPDX Decaying Bonds is not updated on token transfers

Jul '23

Tapioca DAO

Tapioca DAO

1,199.83 USDC • 5 total findings • Code4rena • glcanvas

#41

high

Attacker can pass duplicated reward token addresses to steal the reward of contract `twTAP.sol`

high

Attacker can prevent rewards from being issued to gauges for a given epoch in TapiocaOptionBroker

medium

Incorrect `eligibleAmount` for `AirdropBroker` Phase 3

medium

`TapiocaOptionLiquidityProvision.registerSingularity()` not checking for duplicate assetIds leading to multiple issues.

medium

possible reeentrancy if rewardToken is ERC777 or execute arbitrary code on senders/receivers using hooks

Basin

Basin

70.62 USDC • Code4rena • glcanvas

#22

Mar '23

Canto Identity Subprotocols contest

Canto Identity Subprotocols contest

882.89 USDC • 1 total finding • Code4rena • glcanvas

#6

medium

Incorrect emoji displaying

Neo Tokyo contest

Neo Tokyo contest

48.97 USDC • Code4rena • glcanvas

#20

Wenwin contest

Wenwin contest

21.7 USDC • Code4rena • glcanvas

#26

Jan '23

Canto Identity Protocol contest

Canto Identity Protocol contest

108.6 CANTO • 1 total finding • Code4rena • glcanvas

#11

medium

Multiple accounts can have the same identity

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

1,692.67 USDC • 5 total findings • Code4rena • glcanvas

bronze

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`

medium

Possible scenario for Signature Replay Attack

medium

RabbitHoleReceipt's address might be changed therefore only manual mint will be available

medium

DOS risk if enough tokens are minted in Quest.claim can lead, at least, to transaction fee lost

medium

User may loose rewards if the receipt is minted after quest end time