https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

hubble

Security Researcher

Contact Me

High

7

Total

Medium

28

Total

$53.81K

Total Earnings

#190 All Time

42x

Payouts

silver

2x

2nd Places

bronze

1x

3rd Places

regular

7x

Top 10

All

Code4rena

Dec '24

SecondSwap

SecondSwap

75.16 USDC • 1 total finding • Code4rena • hubble

#37

medium

Missing sellable check in completePurchase will cause a user to buy a token marked as unsellable by S2ADMIN if it was listed beforehand

Nov '24

Concrete

Concrete

5.15 USDC • Code4rena • hubble

#97

Nov '23

Panoptic

Panoptic

11.32 USDC • Code4rena • hubble

#28

Jul '22

Fractional v2 contest

Fractional v2 contest

76.58 USDC • 1 total finding • Code4rena • hubble

#80

medium

An attacker can DoS vault's buyout with as little as 1 wei per 4 days

Juicebox V2 contest

Juicebox V2 contest

1,267.15 USDC • 2 total findings • Code4rena • hubble

#11

high

ORACLE DATA FEED CAN BE OUTDATED YET USED ANYWAYS WHICH WILL IMPACT ON PAYMENT LOGIC

medium

Reentrancy issues on function `distributePayoutsOf`

Jun '22

Putty contest

Putty contest

1,317.61 USDC • 2 total findings • Code4rena • hubble

#14

medium

Put options are free of any fees

medium

Use of Solidity version 0.8.13 which has two known issues applicable to PuttyV2

Yieldy contest

Yieldy contest

156.94 USDC • 1 total finding • Code4rena • hubble

#35

medium

`_storeRebase()` is called with the wrong parameters

May '22

Rubicon contest

Rubicon contest

600.18 USDC • 3 total findings • Code4rena • hubble

#21

high

BathToken LPs Unable To Receive Bonus Token Due To Lack Of Wallet Setter Method

medium

No cap on fees can result in a DOS in BathToken.withdraw()

medium

Early funds withdrawers can get bonus in multiples of vested bonus tokens (e.g. 2-times, 3-times, etc.)

OpenSea Seaport contest

OpenSea Seaport contest

1,892.4 USDC • Code4rena • hubble

#32

Aura Finance contest

Aura Finance contest

149.87 USDC • Code4rena • hubble

#46

Cally contest

Cally contest

3,644.36 USDC • 4 total findings • Code4rena • hubble

silver

high

Inefficiency in the Dutch Auction due to lower duration

medium

Owner can modify the feeRate on existing vaults and steal the strike value on exercise

medium

Owner can set the feeRate to be greater than 100% and cause all future calls to `exercise` to revert

medium

Vault is Not Compatible with Fee Tokens and Vaults with Such Tokens Could Be Exploited

Enso Finance contest

Enso Finance contest

7.8 USDT • Code4rena • hubble

#60

FactoryDAO contest

FactoryDAO contest

173.16 DAI • 1 total finding • Code4rena • hubble

#29

medium

Malicious token reward could disable withdrawals

Cudos contest

Cudos contest

738 USDC • 1 total finding • Code4rena • hubble

#17

medium

Missing check in the updateValset function

Forgotten Runes Warrior Guild contest

Forgotten Runes Warrior Guild contest

89.96 USDC • Code4rena • hubble

#40

bunker.finance contest

bunker.finance contest

13,743.24 USDC • 1 total finding • Code4rena • hubble

silver

medium

CNft.sol - revert inside safeTransferFrom will break composability & standard behaviour

Apr '22

AbraNFT contest

AbraNFT contest

72.4 MIM • Code4rena • hubble

#44

Backd contest

Backd contest

606.22 USDC • 1 total finding • Code4rena • hubble

#17

medium

_revokeRole doesn't remove account from roleMember set

Badger Citadel contest

Badger Citadel contest

93.83 USDC • 1 total finding • Code4rena • hubble

#50

medium

Seven ways in which the Owner and Proxy Admin can make users lose funds ("rug vectors")

JPEG'd contest

JPEG'd contest

168.43 USDC • Code4rena • hubble

#41

Backed Protocol contest

Backed Protocol contest

51.87 USDC • Code4rena • hubble

#34

Mar '22

Volt Protocol contest

Volt Protocol contest

125.78 USDC • Code4rena • hubble

#26

Joyn contest

Joyn contest

1,040.55 USDC • 3 total findings • Code4rena • hubble

#12

high

CoreCollection can be reinitialized

high

Centralisation RIsk: Owner Of `RoyaltyVault` Can Take All Funds

medium

Not handling return value of transferFrom command can create inconsistency

Paladin contest

Paladin contest

4,151.74 USDC • 2 total findings • Code4rena • hubble

bronze

medium

Function cooldown() is not protected when protocol in emergency mode

medium

UserLock information can be found during emergency mode

LI.FI contest

LI.FI contest

113.58 USDC • Code4rena • hubble

#49

Biconomy Hyphen 2.0 contest

Biconomy Hyphen 2.0 contest

200.41 USDT • 1 total finding • Code4rena • hubble

#34

medium

Improper Upper Bound Definition on the Fee

Feb '22

Anchor contest

Anchor contest

7,300.23 UST • 1 total finding • Code4rena • hubble

#7

medium

Updating the hub’s token contract address may lead to incorrect undelegation amount

Foundation contest

Foundation contest

454.89 USDC • Code4rena • hubble

#19

SKALE contest

SKALE contest

5,993.46 USDC • 1 total finding • Code4rena • hubble

#5

medium

Loss of pending messages (if any) in case removeConnectedChain is called

Hubble contest

Hubble contest

250.24 USDC • 1 total finding • Code4rena • hubble

#26

medium

Liquidations can be run on the bogus Oracle prices

Aave Lens contest

Aave Lens contest

524.92 USDC • Code4rena • hubble

#14

Badger Citadel contest

Badger Citadel contest

622.98 USDC • 1 total finding • Code4rena • hubble

#14

medium

Seven ways in which the Owner and Proxy Admin can make users lose funds ("rug vectors")

Concur Finance contest

Concur Finance contest

443.54 USDC • 1 total finding • Code4rena • hubble

#26

medium

During stake or deposit, users would not be rewared the correct Concur token, when MasterChef has under-supply of it.

Jan '22

Trader Joe contest

Trader Joe contest

1,556.92 USDT • 1 total finding • Code4rena • hubble

#12

medium

possibility of minting rJOE tokens before ownership is changed to RocketJoeStaking

InsureDAO contest

InsureDAO contest

527.31 tokens) • Code4rena • hubble

#21

Sandclock contest

Sandclock contest

107.62 USDC • Code4rena • hubble

#25

Dec '21

Amun contest

Amun contest

0 USDC • Code4rena • hubble

#28

PoolTogether TwabRewards contest

PoolTogether TwabRewards contest

556.28 USDC • 1 total finding • Code4rena • hubble

#13

high

cancelPromotion is too rigorous

Perennial contest

Perennial contest

1,253.8 USDC • Code4rena • hubble

#7

Nov '21

Streaming Protocol contest

Streaming Protocol contest

1,340.61 USDC • 1 total finding • Code4rena • hubble

#22

medium

Storage variable unstreamed can be artificially inflated

Overlay Protocol contest

Overlay Protocol contest

2,242.52 ETH • 2 total findings • Code4rena • hubble

#9

high

OZ ERC1155Supply vulnerability

medium

_totalSupply not updated in _transferMint() and _transferBurn()

yAxis contest

yAxis contest

57.06 USDC • Code4rena • hubble

#13