https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/a254af3e-0793-47a7-816d-feaac7052dda.jpg

kiki_dev

Security Researcher

Security Researcher @GuardianAudits | Creativity and will power is all you need

Contact Me

High

11

Total

Medium

13

Total

$892.00

Total Earnings

#1259 All Time

9x

Payouts

regular

4x

Top 25

regular

7x

Top 50

All

Sherlock

Code4rena

May '23

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

143.27 USDC • 9 total findings • Sherlock • kiki_dev

#16

high

Protocol is easy to manipulate due to use of slot0

high

Missing access control on mint/burn functions.

high

`UniV3SwapInput()` Missing slippage protection

high

Missing working address for ethOracle

high

Likely overflow when multiplying in getOwnValuation()

high

BuyUSSDSellCollateral will underflow when collaterValue is greater than 1e18

medium

`getPriceUSD()` will return the wrong price when outside of min/max range

medium

Missing checks will return stale or 0 price

medium

StableOracleWBTC() uses BTC pricefeed for WBTC

Footium

Footium

298.89 USDC • 3 total findings • Sherlock • kiki_dev

#11

high

Buyer of club owner can be frontrun by owner of club

medium

Unsafe minting of footiumClubs

medium

Unsafe transfer of arbitrary erc20 token

Feb '23

Surge

Surge

6.94 USDC • 1 total finding • Sherlock • kiki_dev

#21

medium

Frontrunning with allowence can cause users to loose funds.

OlympusDAO

OlympusDAO

56.54 USDC • 1 total finding • Sherlock • kiki_dev

#31

medium

Once reward token is removed users wont have access to their yield.

OpenQ

OpenQ

40.01 USDC • 4 total findings • Sherlock • kiki_dev

#42

high

Unbound loop in getLockedFunds() can cause DOS preventing refunds.

high

malicious or paused tokens can cause claiming to fail.

medium

Token Address Limit can be reached by sending dust amounts of junk tokens.

medium

Max out nft deposit with low value ones making bounty undesirable.

Jan '23

Cooler

Cooler

257.89 USDC • 2 total findings • Sherlock • kiki_dev

#14

high

Unsafe Transfer of arbitrary erc20 tokens.

medium

If user repays more than what is owed the function will revert.

Dec '22

GoGoPool contest

GoGoPool contest

40.88 USDC • 1 total finding • Code4rena • kiki_dev

#70

medium

wrong reward distribution between early and late depositors because of the late syncRewards() call in the cycle, syncReward() logic should be executed in each withdraw or deposits (without reverting)

Caviar contest

Caviar contest

45.94 USDC • 1 total finding • Code4rena • kiki_dev

#43

medium

Rounding error in buyQuote might result in free tokens

Escher contest

Escher contest

2.18 USDC • 2 total findings • Code4rena • kiki_dev

#65

high

`LPDA` price can underflow the price due to bad settings and potentially brick the contract

medium

ETH will get stuck if all NFTs do not get sold.