https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

inspecktor

Security Researcher

Contact Me

High

3

Total

Medium

11

Total

$1.88K

Total Earnings

#1040 All Time

12x

Payouts

regular

2x

Top 25

regular

4x

Top 50

All

Sherlock

Code4rena

Aug '24

Chakra

Chakra

0.07 USDT • 1 total finding • Code4rena • Inspecktor

#65

high

There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` function

Phi

Phi

0.19 USDC • 1 total finding • Code4rena • Inspecktor

#54

high

Exposed `_removeCredIdPerAddress` & `_addCredIdPerAddress` allows anyone to cause issues to current holders as well as upcoming ones

Jul '24

LoopFi

LoopFi

2.09 USDC • 1 total finding • Code4rena • Inspecktor

#54

medium

WhenNotPaused modifier in the CDPVault can be bypassed by users

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

2.76 USDC • Code4rena • Inspecktor

#54

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

25.79 USDC • 1 total finding • Code4rena • Inspecktor

#54

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

Allo V2

Allo V2

0.09 USDC • 1 total finding • Sherlock • inspecktor

#74

medium

Using tokens with a transfer fee may result in the loss of funds of recent users

Ondo Finance

Ondo Finance

904.14 USDC • 2 total findings • Code4rena • Inspecktor

#11

medium

Admin can't burn tokens from blocklisted addresses because of a check in _beforeTokenTransfer

medium

TWO DIFFERENT TRANSACTIONS CAN RESULT IN THE SAME `txnHash` VALUE THUS BREAKING THE APPROVAL PROCESS OF TRANSACTION MINTING

Aug '23

Dopex

Dopex

537.51 USDC • 3 total findings • Code4rena • Inspecktor

#36

medium

The RdpxV2Core contract allows anyone to call redeem tokens even if the contract is paused.

medium

Can not withdraw RDPX if WETH withdrawn is zero

medium

A malicious early depositor can manipulate the `LP-Token` price per share to take an unfair share of future user deposits

Tangible Caviar

Tangible Caviar

0 USDC • Code4rena • Inspecktor

#88

Jul '23

PoolTogether

PoolTogether

201.15 USDC • 2 total findings • Code4rena • Inspecktor

#43

medium

Attacker can frontrun deployVault to deploy at the same address

medium

`drawManager` CAN BE SET TO A MALICIOUS ADDRESS

Basin

Basin

180.46 USDC • 1 total finding • Code4rena • Inspecktor

#15

medium

boreWell can be frontrun/DoS-d

Jun '23

Lybra Finance

Lybra Finance

29.06 USDC • 1 total finding • Code4rena • Inspecktor

#76

medium

`stakerewardV2pool.withdraw()` should check the user's boost lock status.