https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/6236a9dd-5275-481e-822c-1cce59622560.jpeg

hyuunn

Security Researcher

@CyKorKU

Contact Me

High

20

Total

Medium

21

Total

$6.25K

Total Earnings

#692 All Time

13x

Payouts

bronze

1x

3rd Places

regular

8x

Top 10

regular

11x

Top 25

All

Code4rena

Cantina

CodeHawks

Mar '25

EIP7702Proxy

EIP7702Proxy

2,237.68 USDC • 1 total finding • Cantina • songhyun

bronze

medium

Finding not yet public.

Feb '25

THORWallet

THORWallet

0 USDC • 1 total finding • Code4rena • hyuunn

#10

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Core Contracts

Core Contracts

1,736.85 usdc • 23 total findings • CodeHawks • bshyuunn

#5

high

ZENO Token Redemption Returns Negligible USDC Amount Compared to Purchase Price

high

Incorrect decimal handling in `Auction::buy()` leads to massive overpayment for ZENO tokens

high

RAACNFT mint function receives funds to address(this) but has no way of withdrawing them

high

Multiple issues from unnecessary balance increase calculation in DebtToken.mint

high

RToken's transfer function lead to loss of funds due to incorrect math

high

Users can borrow more assets than they have deposited as collateral

high

Critical Economic Design Flaw in ZENO Zero-Coupon Bond Implementation Leads to Guaranteed User Losses

high

Scaled Allowance Mismatch Enables Over-Approval Exploit

medium

Incorrect DebtToken totalSupply Scaling Breaks Interest Rate Calculations

medium

Incorrect Return Values and Double Scaling in `RToken.burn` Function Leads to Denial of Service

medium

RToken.transferFrom() Does Not Scale User Balances Due to Stale Liquidity Index

medium

LendingPool::getNormalizedIncome() returns stale liquidity index

medium

Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check

medium

`RToken::calculateDustAmount` are incorrectly calculated, leading to not be able to transfer the accrued dust amount

medium

Concurrent Oracle Fulfillments Overwrite House IDs, which leads to Incorrect Pricing

medium

Liquidations are enabled when repayments are disabled, causing borrowers to lose funds without a chance to repay

medium

Due to not counting the assets stake on crvVault the reported amount of dust will not be correct

medium

getNormalizedDebt will return a wrong Amount when Timedelta is 0.

low

Impossible to rescue funds from `RToken` contract

low

Incorrect Timestamp Tracking in RAACHousePrice contract

low

Incorrect Comparison Between Scaled and Unscaled Amounts in _repay

low

If the Rtoken Contract is minted with 0 amount, an invalid value is returned.

low

Missing Burn Functionality in RAACNFT

Jan '25

Next Generation

Next Generation

227.2 USDC • 2 total findings • Code4rena • hyuunn

#8

high

Cross-Chain Signature Replay Attack Due to User-Supplied `domainSeparator` and Missing Deadline Check

medium

Lack of deadline check in forwarded request

Liquid Ron

Liquid Ron

0.03 USDC • 2 total findings • Code4rena • hyuunn

#10

high

The calculation of `totalAssets()` could be wrong if `operatorFeeAmount` > 0, this can cause potential loss for the new depositors

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

daao-contracts

daao-contracts

295.06 USDC • 7 total findings • Cantina • songhyun

#14

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Aave DIVA Wrapper

Aave DIVA Wrapper

28.54 usdc • 1 total finding • CodeHawks • bshyuunn

#7

low

The Aave pool is hardcoded

dahlia-protocol

dahlia-protocol

1,105.3 USDC • 1 total finding • Cantina • songhyun

#17

high

Finding not yet public.

reserve-index-dtf

reserve-index-dtf

53.43 USDC • 1 total finding • Cantina • songhyun

#8

medium

Finding not yet public.

Dec '24

QuantAMM

QuantAMM

147.50 op • 4 total findings • CodeHawks • bshyuunn

#43

high

Critical: Malicious user can delete all Users Deposited Liquidity.

high

Fee Evasion via LP Token Transfer Resets Deposit Value

medium

Incorrect Handling Of Nft Self-Transfer In afterupdate Hook Allows The Owner To Grief A Buyer By Rendering The Nft Unable To Redeem Its Associated Liquidity, Resulting In A Loss Of Funds

medium

Transferring deposit NFT doesn't check if the receiver exceeds the 100 deposit limit

Alchemix Transmuter

Alchemix Transmuter

230.50 op • 4 total findings • CodeHawks • bshyuunn

#20

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

low

Missing Router Update Mechanism in StrategyMainnet Contract

low

Inconsistent Shutdown Enforcement Allows Asset Deployment Post-Shutdown

low

Strategy can miss capturing funds from positive slippage due to no deadline check on swaps

InterPol

InterPol

156.87 USDC • 1 total finding • Cantina • songhyun

#10

high

Finding not yet public.

Lambo.win

Lambo.win

34.72 USDC • 2 total findings • Code4rena • hyuunn

#28

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

medium

`sellQuote` and `buyQuote` are missing deadline check in `LamboVEthRouter`