https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/09a45d5f-9854-4618-918a-8f72c4a2c764.jpg

inzinko

Security Researcher

Web3 Security Researcher

Contact Me

High

11

Total

Medium

1

Solo

17

Total

$2.31K

Total Earnings

#974 All Time

16x

Payouts

regular

4x

Top 25

regular

9x

Top 50

All

Sherlock

Code4rena

CodeHawks

Aug '24

Tadle

Tadle

502.29 USDC • 5 total findings • CodeHawks • inzinko

#11

high

TokenManager - Unlimited withdraw

high

Taker of bid offer will loss assets without any benefit if he calls the DeliveryPlace::settleAskMaker() for partial settlement.

high

Formulaic Error Rounds Down Causing Total Loss Of Funds For Bid Takers During Abort

high

Missing abort status check allows bid taker to steal users funds

low

`listOffer` Unsafely References Fungible Identifiers

Jul '24

TraitForge

TraitForge

118.21 USDC • 8 total findings • Code4rena • inzinko

#37

high

`mintToken()`, `mintWithBudget()`, and `forge()` in the `TraitForgeNft` Contract Will Fail Due to a Wrong Modifier Used in `EntropyGenerator.initializeAlphaIndices()`

high

The maximum number of generations is infinite

high

Number of entities in generation can surpass the 10k number

high

Griefing attack on seller's airdrop benefits

high

Wrong minting logic based on total token count across generations

medium

Forger Entities can forge more times than intended

medium

Imprecise token age calculation results in an incorrect nuke factor, causing users to claim the wrong amount

medium

Discrepancy between nfts minted, price of nft when a generation changes & position of `_incrementGeneration()` inside `_mintInternal()` & `_mintNewEntity()`

Zaros Part 1

Zaros Part 1

13.91 USDC • 2 total findings • CodeHawks • inzinko

#83

low

Functions calling `verifyReport` to verify offchain prices from chainlink will fail

low

Deleting CollateralTypes from the CollateralLiquidationPriority allows traders to be liquidated for free and getting back their full collateral as if they were not liquidated.

CCIP v1.5

CCIP v1.5

118.59 USDC • CodeHawks • inzinko

#14

Jun '24

Size

Size

726.81 USDC • 5 total findings • Code4rena • inzinko

#31

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

medium

`executeBuyCreditMarket` returns the wrong amount of cash and overestimates the amount that needs to be checked in the variable pool

medium

Users can not to buy/sell minimum credit allowed due to exactAmountIn condition

medium

Multicall does not work as intended

medium

withdraw() users may can't withdraw underlyingBorrowToken properly

Apr '24

Renzo

Renzo

18.24 USDC • 2 total findings • Code4rena • inzinko

#40

medium

Pending withdrawals prevent safe removal of collateral assets

medium

Deposits will always revert if the amount being deposited is less than the bufferToFill value

Feb '24

AI Arena

AI Arena

0.23 USDC • 1 total finding • Code4rena • inzinko

#179

medium

DoS in `MergingPool::claimRewards` function and potential DoS in `RankedBattle::claimNRN` function if called after a significant amount of rounds passed.

Jan '24

Salty.IO

Salty.IO

90.94 USDC • 1 total finding • Code4rena • inzinko

#71

medium

Creation of token whitelisting proposals can be DOS'd

Dec '23

The Standard

The Standard

20.77 USDC • 3 total findings • CodeHawks • inzinko

#52

medium

Fees are hardcoded to 3000 in ExactInputSingleParams

medium

Wrong Implementation of `LiquidationPool::empty` excludes holder with pending stakes when decreasing a position, resulting in exclusion from asset distribution

low

Removal of approved token from token manager can lead to unintended liquidation of vaults

Nov '23

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

1.37 USDC • 1 total finding • Code4rena • inzinko

#31

medium

No slippage protection for Market functions

Oct '23

NextGen

NextGen

0 USDC • 1 total finding • Code4rena • inzinko

#115

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

Steadefi

Steadefi

673.66 USDC • 2 total findings • CodeHawks • inzinko

#11

medium

GMXVault can stop working in case if GMX will change `Keys.MAX_CALLBACK_GAS_LIMIT` to smaller than 2 millions

medium

The State of the Vault can be stuck for a long period of time

The Wildcat Protocol

The Wildcat Protocol

10.17 USDC • Code4rena • inzinko

#67

ENS

ENS

10.69 USDC • Code4rena • inzinko

#18

Sep '23

Venus Prime

Venus Prime

4.37 USDC • Code4rena • inzinko

#39

Allo V2

Allo V2

0.09 USDC • 1 total finding • Sherlock • inzinko

#74

medium

Amount of Funds in pool inconsistent with expected amount