Security Researcher
Independent Security Researcher | Solidity | sherlock | immunefi | Cantina. My username on Cantina is GeneralKay
High
Total
Medium
Total
Total Earnings
#273 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
CodeHawks
Immunefi
Mar '25
high
medium
high
Feb '25
medium
medium
Jan '25
high
high
high
high
high
Dec '24
medium
medium
medium
Oct '24
high
high
medium
Aug '24
medium
medium
Jul '24
high
AuraVault inherits AccessControl BUT does not call the _setupRole() function in it's constructor to set the initial roles, this leads to a complete DOS of the important claim function rendering the contract unable to claim rewards
medium
WhenNotPaused modifier in the CDPVault can be bypassed by users
medium
`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`
medium
INFLATION_PROTECTION_TIME can not be up to a year as intended because it is hardcoded to `1749120350`
May '24
Apr '24
high
`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`
medium
Attacker can increase the length of `withdrawQueue` by withdrawing 0 amount of tokens frequently
medium
`CurveConnector` will be non-functional on Arbitrum & Polygon due to the improper integration with Convex Boosters on these chains
medium
Using the same heartbeat for multiple price feeds
Feb '24
high
high
medium
medium
medium
medium
medium
low
high
high
Jan '24
Dec '23
Nov '23
Oct '23
Sep '23
Aug '23
Jul '23
Jun '23
Apr '23
Mar '23
Feb '23
Jan '23