https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/fccfc7a5-7843-434f-8f83-9e66f1064866.jpg

korok

Security Researcher

security researcher @theTrustlessDAO

Contact Me

High

10

Total

Medium

11

Total

$2.63K

Total Earnings

#996 All Time

15x

Payouts

regular

4x

Top 10

regular

7x

Top 25

regular

11x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

May '25

stability-contracts

stability-contracts

77.49 USDC • 1 total finding • Cantina • korok

#26

high

Finding not yet public.

mystic-monorepo

mystic-monorepo

4.93 USDC • 1 total finding • Cantina • korok

#71

medium

Finding not yet public.

Apr '25

mighty-contracts

mighty-contracts

51.66 USDC • 2 total findings • Cantina • korok

#42

high

Finding not yet public.

high

Finding not yet public.

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • korok

#18

medium

Attacker Can Perform Arbitrary Rate Reduction and Period Extension on Stakers

Feb '25

size-solidity

size-solidity

171.52 USDC • 1 total finding • Cantina • korok

#4

medium

Finding not yet public.

velvet-v4

velvet-v4

1,273.62 USDC • 1 total finding • Cantina • korok

#10

high

Finding not yet public.

TermMax

TermMax

253.76 USDC • Cantina • korok

#6

Jan '25

Part 2

Part 2

279.83 usdc • 1 total finding • CodeHawks • smol_korok

#32

medium

Negative Credit Capacity Handling Causes Complete Vault Lockout When Underwater

Aug '24

Cork Protocol

Cork Protocol

91.50 USDC • 2 total findings • Sherlock • korok

#13

high

Incorrect Price Ratio Calculation in calculateProvideLiquidityAmountBasedOnCtPrice Function

medium

Incorrect Pause Flag Check in LVDepositNotPaused Modifier

Winnables Raffles

Winnables Raffles

0.76 USDC • 1 total finding • Sherlock • korok

#38

medium

Incorrect Bit Manipulation Leads to Immutable Roles

Jul '24

TraitForge

TraitForge

0 USDC • 1 total finding • Code4rena • korok

#89

medium

Pause and unpause functions are inaccessible

Union Finance Update #2

Union Finance Update #2

256.42 USDC • 2 total findings • Sherlock • korok

#7

high

VouchFaucet can be immediately drained by anyone

medium

Arbitrary ERC1155 Token Transfer Grants Unintended Trust in ERC1155Voucher Contract

May '24

Elfi

Elfi

55.68 USDC • 1 total finding • Sherlock • korok

#23

medium

`revokeAllRole()` corrupts the EnumerableSet leaving the targets permissions active and making their role unrevokable

Apr '24

NOYA

NOYA

0.18 USDC + NOYA stars • 1 total finding • Code4rena • korok

#121

medium

Incorrect modifier condition

Feb '24

AI Arena

AI Arena

113.09 USDC • 5 total findings • Code4rena • korok

#54

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

high

FighterFarm:: reroll won't work for nft id greator than 255 due to input limited to uint8

medium

Can mint NFT with the desired attributes by reverting transaction