https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/22636bcd-9cba-4edf-888c-8caebdb75121.jpg

jorgect

Security Researcher

Mechanical engineering turning to Smart contract security researcher, Web3 Maximalist, I like NFT

Contact Me

High

19

Total

Medium

24

Total

$8.00K

Total Earnings

#653 All Time

27x

Payouts

regular

2x

Top 10

regular

8x

Top 25

regular

18x

Top 50

All

Code4rena

Aug '24

Phi

Phi

60.38 USDC • 4 total findings • Code4rena • Jorgect

#20

high

Reentrancy Vulnerability Allows Bypass of Cooldown, Leading to Unfair Reward Extraction Through Flash Loan

high

`shareBalance` bloating eventually blocks curator rewards distribution

high

Signature replay in `createArt` allows to impersonate artist and steal royalties

medium

Attacker can DOS user from selling shares of a credId

Jun '24

Size

Size

23.36 USDC • 4 total findings • Code4rena • Jorgect

#49

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

medium

Fragmentation fee is not taken if user compensates with newly created position

medium

Users can not to buy/sell minimum credit allowed due to exactAmountIn condition

medium

Multicall does not work as intended

Apr '24

NOYA

NOYA

211.53 USDC + NOYA stars • 6 total findings • Code4rena • Jorgect

#37

medium

`AccountingManager#totalWithdrawnAmount` should reflect tokens actually transferred to users, instead of expected transfers

medium

First depositor can make subsequent depositor lose all of her or his deposit

medium

`performanceFeeReceiver` cannot mint any performance fee shares even if TVL is dropped by only a very tiny amount

medium

setFees doesn't collect previous fees before changing fee values

medium

`depositQueue.queue` in `AccountingManager` can be flooded causing a DoS

medium

Using the same heartbeat for multiple price feeds

DYAD

DYAD

513.93 USDC • 7 total findings • Code4rena • Jorgect

#17

high

Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral

high

Kerosene collateral is not being moved on liquidation, exposing liquidators to loss

high

User can get their Kerosene stuck because of an invalid check on withdraw

high

Attacker Can Frontruns User's Withdrawals To Make Them Reverts Without Costs

medium

`VaultManagerV2.sol::burnDyad` function is missing an `isDNftOwner` modifier, allowing a user to burn another user's minted DYAD

medium

Attacker can frontrun to prevent vaults from being removed from the dNFT owner's position

medium

Value of kerosene can be manipulated to force liquidate users

Mar '24

Smart Wallet

Smart Wallet

2,629.91 USDC • 1 total finding • Code4rena • Jorgect

#4

medium

Users can front run the signature of the paymaster operation leading to some problems.

Feb '24

Wise Lending

Wise Lending

1,378 USDC • 2 total findings • Code4rena • Jorgect

#16

medium

Borrowers can DoS liquidations by repaying as little as 1 share.

medium

Unchecked return value bug on `TransferHelper::_safeTransferFrom()`

AI Arena

AI Arena

1.05 USDC • 3 total findings • Code4rena • Jorgect

#170

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)

medium

Can mint NFT with the desired attributes by reverting transaction

Jan '24

Salty.IO

Salty.IO

212.92 USDC • 4 total findings • Code4rena • Jorgect

#52

high

When borrowers repay USDS, it is sent to the wrong address, allowing anyone to burn Protocol Owned Liquidity and build bad debt for USDS

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

medium

THE USER WHO WITHDRAWS LIQUIDITY FROM A PARTICULAR POOL IS ABLE TO CLAIM MORE REWARDS THAN HE DULY DESERVES BY CAREFULLY SELECTING A `decreaseShareAmount` VALUE SUCH THAT THE `virtualRewardsToRemove` IS ROUNDED DOWN TO ZERO

medium

formPOL lacks slippage and deadline protection

reNFT

reNFT

71.91 USDC • Code4rena • Jorgect

#43

Dec '23

Ethereum Credit Guild

Ethereum Credit Guild

273.5 USDC • 2 total findings • Code4rena • Jorgect

#45

high

Anyone can steal all distributed rewards

medium

Anyone can prolong the time for the rewards to get distributed

Oct '23

NextGen

NextGen

35.61 USDC • 2 total findings • Code4rena • Jorgect

#70

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

medium

On a Linear or Exponential Descending Sale Model, a user that mint on the last `block.timestamp` mint at an unexpected price.

zkSync Era

zkSync Era

95.22 USDC • Code4rena • Jorgect

#37

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

11.58 USDC • 1 total finding • Code4rena • Jorgect

#59

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

645.16 USDC • Code4rena • Jorgect

#36

Dopex

Dopex

0.07 USDC • 1 total finding • Code4rena • Jorgect

#126

high

The peg stability module can be compromised by forcing lowerDepeg to revert.

Shell Protocol

Shell Protocol

22.46 USDC • Code4rena • Jorgect

#18

veRWA

veRWA

31.67 USDC • 1 total finding • Code4rena • Jorgect

#45

high

Users may be forced into long lock times to be able to undelegate back to themselves.

PoolTogether V5: Part Deux

PoolTogether V5: Part Deux

89.63 USDC • 1 total finding • Code4rena • Jorgect

#24

high

`rngComplete` function should only be called by `rngAuctionRelayer`

Jul '23

Moonwell

Moonwell

44.88 USDC • Code4rena • Jorgect

#36

PoolTogether

PoolTogether

19.29 USDC • 1 total finding • Code4rena • Jorgect

#65

medium

`drawManager` CAN BE SET TO A MALICIOUS ADDRESS

Basin

Basin

6.07 USDC • Code4rena • Jorgect

#29

Jun '23

Lybra Finance

Lybra Finance

84.36 USDC • 1 total finding • Code4rena • Jorgect

#59

medium

If `ProtocolRewardsPool` is insufficient in EUSD, users will not be able to calim any rewards

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

62.33 USDC • 1 total finding • Code4rena • Jorgect

#64

high

TalosBaseStrategy#init() lacks slippage protection

Chainlink Cross-Chain Services: CCIP and ARM Network

Chainlink Cross-Chain Services: CCIP and ARM Network

255.8 USDC • Code4rena • Jorgect

#39

Ajna Protocol

Ajna Protocol

1,135.45 USDC • 1 total finding • Code4rena • Jorgect

#9

high

missing isEpochClaimed validation

Apr '23

ENS Contest

ENS Contest

59.79 USDC • Code4rena • Jorgect

#20

Frankencoin

Frankencoin

22.6 USDC • Code4rena • Jorgect

#66