Security Researcher
High
Total
Medium
Total Earnings
#1040 All Time
Payouts
Top 25
Top 50
All
Sherlock
Code4rena
Aug '24
0.07 USDT • 1 total finding • Code4rena • Inspecktor
#65
high
There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` function
0.19 USDC • 1 total finding • Code4rena • Inspecktor
#54
Exposed `_removeCredIdPerAddress` & `_addCredIdPerAddress` allows anyone to cause issues to current holders as well as upcoming ones
Jul '24
2.09 USDC • 1 total finding • Code4rena • Inspecktor
medium
WhenNotPaused modifier in the CDPVault can be bypassed by users
Nov '23
2.76 USDC • Code4rena • Inspecktor
Sep '23
25.79 USDC • 1 total finding • Code4rena • Inspecktor
All tokens can be stolen from `VirtualAccount` due to missing access modifier
0.09 USDC • 1 total finding • Sherlock • inspecktor
#74
Using tokens with a transfer fee may result in the loss of funds of recent users
904.14 USDC • 2 total findings • Code4rena • Inspecktor
#11
Admin can't burn tokens from blocklisted addresses because of a check in _beforeTokenTransfer
TWO DIFFERENT TRANSACTIONS CAN RESULT IN THE SAME `txnHash` VALUE THUS BREAKING THE APPROVAL PROCESS OF TRANSACTION MINTING
Aug '23
537.51 USDC • 3 total findings • Code4rena • Inspecktor
#36
The RdpxV2Core contract allows anyone to call redeem tokens even if the contract is paused.
Can not withdraw RDPX if WETH withdrawn is zero
A malicious early depositor can manipulate the `LP-Token` price per share to take an unfair share of future user deposits
0 USDC • Code4rena • Inspecktor
#88
Jul '23
201.15 USDC • 2 total findings • Code4rena • Inspecktor
#43
Attacker can frontrun deployVault to deploy at the same address
`drawManager` CAN BE SET TO A MALICIOUS ADDRESS
180.46 USDC • 1 total finding • Code4rena • Inspecktor
#15
boreWell can be frontrun/DoS-d
Jun '23
29.06 USDC • 1 total finding • Code4rena • Inspecktor
#76
`stakerewardV2pool.withdraw()` should check the user's boost lock status.