https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/fccfc7a5-7843-434f-8f83-9e66f1064866.jpg

korok

Security Researcher

security researcher @theTrustlessDAO

Contact Me

High

6

Total

Medium

10

Total

$1.22K

Total Earnings

#1180 All Time

11x

Payouts

regular

3x

Top 10

regular

6x

Top 25

regular

8x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • korok

#18

medium

Attacker Can Perform Arbitrary Rate Reduction and Period Extension on Stakers

Feb '25

size-solidity

size-solidity

171.52 USDC • 1 total finding • Cantina • korok

#4

medium

Finding not yet public.

TermMax

TermMax

253.76 USDC • Cantina • korok

#6

Jan '25

Part 2

Part 2

279.83 usdc • 1 total finding • CodeHawks • smol_korok

#32

medium

Negative Credit Capacity Handling Causes Complete Vault Lockout When Underwater

Aug '24

Cork Protocol

Cork Protocol

91.50 USDC • 2 total findings • Sherlock • korok

#13

high

Incorrect Price Ratio Calculation in calculateProvideLiquidityAmountBasedOnCtPrice Function

medium

Incorrect Pause Flag Check in LVDepositNotPaused Modifier

Winnables Raffles

Winnables Raffles

0.76 USDC • 1 total finding • Sherlock • korok

#38

medium

Incorrect Bit Manipulation Leads to Immutable Roles

Jul '24

TraitForge

TraitForge

0 USDC • 1 total finding • Code4rena • korok

#89

medium

Pause and unpause functions are inaccessible

Union Finance Update #2

Union Finance Update #2

256.42 USDC • 2 total findings • Sherlock • korok

#7

high

VouchFaucet can be immediately drained by anyone

medium

Arbitrary ERC1155 Token Transfer Grants Unintended Trust in ERC1155Voucher Contract

May '24

Elfi

Elfi

55.68 USDC • 1 total finding • Sherlock • korok

#23

medium

`revokeAllRole()` corrupts the EnumerableSet leaving the targets permissions active and making their role unrevokable

Apr '24

NOYA

NOYA

0.18 USDC + NOYA stars • 1 total finding • Code4rena • korok

#121

medium

Incorrect modifier condition

Feb '24

AI Arena

AI Arena

113.09 USDC • 5 total findings • Code4rena • korok

#54

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

high

FighterFarm:: reroll won't work for nft id greator than 255 due to input limited to uint8

medium

Can mint NFT with the desired attributes by reverting transaction