https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/c5d0798d-e9ae-47ce-b4dd-a25de87b6ec0.jpg

Greed

Security Researcher

I meme about blockchain security on Twitter and sometimes I find vulnerabilities

High

14

Total

Medium

17

Total

$9.17K

Total Earnings

#575 All Time

23x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

9x

Top 10

All

Sherlock

Code4rena

Cantina

CodeHawks

Immunefi

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

39.69 USDC • 1 total finding • Sherlock • Greed

#15

medium

Nested initializer prevents `SymmVesting` from being deployed

Jan '25

IQ AI

IQ AI

1,392.11 USDC • 2 total findings • Code4rena • Greed

bronze

high

Adversary can win proposals with voting power as low as 4%

medium

[M-3] Anyone can deploy a new `FraxSwapPair` with a Low fee incurring losses to the protocol

Dec '24

InterPol

InterPol

97.83 USDC • 1 total finding • Cantina • Greed

#23

medium

Finding not yet public.

Nov '24

Debita Finance V3

Debita Finance V3

7.88 USDC • 1 total finding • Sherlock • Greed

#54

high

NFTs sold in `buyOrder` can't be retrieved due to missing functionality

Telcoin Update #2

Telcoin Update #2

39.32 USDC • Sherlock • Greed

#26

Oct '24

Flow

Flow

865.89 USDC • 1 total finding • CodeHawks • greed

#6

low

Flow stream cannot be created for tokens that do not implement the `decimals` function

Gamma Brevis Rewarder

Gamma Brevis Rewarder

314.34 OP • 1 total finding • Sherlock • Greed

silver

medium

Loss of dust tokens in distribution calculation

Sep '24

symbioticfi-core

symbioticfi-core

211.51 USDC • 1 total finding • Cantina • Greed

#24

medium

Finding not yet public.

Aug '24

Velar Artha PerpDEX

Velar Artha PerpDEX

116.00 USDC • 1 total finding • Sherlock • Greed

#7

medium

The use of `tx.origin` may cause a trader to lose funds

Fjord Token Staking

Fjord Token Staking

94.68 USDC • 1 total finding • CodeHawks • greed

#17

medium

Epoch mismatch in FjordPoints and FjordStaking leads to user being able to stake and unstake instantly for rewards

Jul '24

Zaros Part 1

Zaros Part 1

134.42 USDC • 6 total findings • CodeHawks • greed

#43

high

Inadequate Checking of `isIncreasing` when trader adjusts position size

high

Incorrect logic for checking isFillPriceValid

medium

A malicious User can DOS all offchain orders making them unexecutable and leaving the protocol in an insolvent state. Also all offchain Trades can also be DOSed for honest parties that do not meet the fillorder requirements (no try and catch)

low

Offchain orders are not cancelled after the account has been liquidated

low

payable Modifier in TradingAccountBranch::createTradingAccountAndMulticall

low

Fees are not sent to their respective recipients when dealing with low decimals tokens

Jun '24

eBTC Zap Router

eBTC Zap Router

2,356.92 USDC • 1 total finding • Code4rena • Greed

#4

medium

Staking ETH incorrectly assumes revert bubbling

Thorchain

Thorchain

596.13 USDC • 2 total findings • Code4rena • Greed

#10

high

ThorChain will be informed wrongly about the unsuccessful ETH transfers due to the incorrect events emissions

medium

[M-02] Incorrect call argument in `THORChain_Router::_transferOutAndCallV5`, leading to grief/steal of `THORChain_Aggregator`'s funds or DoS

May '24

Sablier

Sablier

982.48 USDC • 2 total findings • CodeHawks • greed

#8

medium

Insufficient input validation on `SablierV2NFTDescriptor::safeAssetSymbol` allows an attacker to obtain stored XSS

low

Malicious user can honeypot other users to buy their stream on an NFT marketplace and cancel it right before the purchase happens

LoopFi

LoopFi

386.08 USDC • 1 total finding • Code4rena • Greed

bronze

high

Availability of deposit invariant can be bypassed

Apr '24

Renzo

Renzo

0 USDC • 1 total finding • Code4rena • Greed

#58

high

Incorrect withdraw queue balance in TVL calculation

Mar '24

Audit Comp | Immunefi Arbitration

Audit Comp | Immunefi Arbitration

1,269 USDC • 1 total finding • Immunefi • greed

#6

low

Finding not yet public.

PoolTogether

PoolTogether

1.47 USDC • 1 total finding • Code4rena • Greed

#29

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

Feb '24

AI Arena

AI Arena

178.47 USDC • 6 total findings • Code4rena • Greed

#32

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

high

FighterFarm:: reroll won't work for nft id greator than 255 due to input limited to uint8

medium

Minter / Staker / Spender roles can never be revoked`..,

medium

Can mint NFT with the desired attributes by reverting transaction

medium

Constraints of dailyAllowanceReplenishTime and allowanceRemaining during mint() can be bypassed by using alias accounts & safeTransferFrom()

medium

DoS in `MergingPool::claimRewards` function and potential DoS in `RankedBattle::claimNRN` function if called after a significant amount of rounds passed.

Jan '24

Decent

Decent

0.12 USDC • 1 total finding • Code4rena • Greed

#55

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

Dec '23

The Standard

The Standard

58.79 USDC • 2 total findings • CodeHawks • greed

#31

high

Rewards can be drained because of lack of access control

medium

Anyone can call the burn function in SmartVaultV3.sol

Oct '23

NextGen

NextGen

2.77 USDC • 2 total findings • Code4rena • Greed

#102

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders

Open Dollar

Open Dollar

22 USDC • 1 total finding • Code4rena • Greed

#52

medium

`ODSafeManager#allowSAFE()` cannot be executed either by the proxy contract or any other address.