https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/04264870-6b63-4801-8788-2a0e41e9f244.jpg

lanrebayode77

Security Researcher

Smart contract security researcher

Contact Me

High

26

Total

Medium

28

Total

$73.46K

Total Earnings

#116 All Time

37x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

bronze

2x

3rd Places

All

Sherlock

Code4rena

Cantina

CodeHawks

Jan '25

dahlia-protocol

dahlia-protocol

6,462.74 USDC • 3 total findings • Cantina • Lanrebayode77

silver

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Aave v3.3

Aave v3.3

628.96 USDC • Sherlock • lanrebayode77

#36

farcasterattestation-monorepo

farcasterattestation-monorepo

84.96 OP • 1 total finding • Cantina • Lanrebayode77

#32

high

Finding not yet public.

Dec '24

Alchemix Transmuter

Alchemix Transmuter

11.67 op • 1 total finding • CodeHawks • lanrebayode77

#27

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

story-protocol

story-protocol

38,827.65 USDC • 1 total finding • Cantina • Lanrebayode77

#7

high

Finding not yet public.

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

3.56 OP • 4 total findings • Sherlock • lanrebayode77

#40

high

Canceled orders can be modified to drain protocol

high

No validation on msg.sender when creating order

high

Creating multiple orders in a multi-call function can be used to steal funds from StopLimit/Bracket contract

high

Use of fallback to steal from OracleLess contract

Nov '24

collar-core

collar-core

697.53 USDC • 1 total finding • Cantina • Lanrebayode77

#11

medium

Finding not yet public.

Debita Finance V3

Debita Finance V3

32.94 USDC • 2 total findings • Sherlock • lanrebayode77

#40

high

Sold NFT will remain stucked in BuyOrder Contract

medium

An attacker can steal the entire borrow and lending incentive of an epoch with FLASHLOAN in a single transaction

Oct '24

Usual V1

Usual V1

1,013.20 USDC • 1 total finding • Sherlock • lanrebayode77

bronze

high

Max withdrawal will cost protocol lost of 5% of the total fee to be collected

Jul '24

LoopFi

LoopFi

392.4 USDC • 4 total findings • Code4rena • lanrebayode77

#24

medium

Discrepency b/w the `lastRewadTime` and the `lastAllPoolUpdate` can allow for incorrect reward distribution to pools if `registerRewardDeposit` deposits less assets

medium

Usage of `lastEligibleStatus` can cause user to miss out on rewards on `manualStopEmissionsFor` invocation

medium

In CDPVault::liquidatePositionBadDebt(), the calculation of `loss` is incorrect.

medium

PositionAction.decreaseLever() fails to consider the loan fee in Flashlender when calculating loanAmount, as a result, the functionanlity will not work when protocolFee != 0.

Karak Restaking

Karak Restaking

1,231.15 USDC • 3 total findings • Code4rena • lanrebayode77

#7

high

Slashing NativeVault will lead to locked ETH for the users

high

The operator can create a `NativeVault` that can be silently unslashable.

medium

Delayed Slashing Window and Lack of Transparency for Pending Slashes Could Lead to Loss of Funds

CCIP v1.5

CCIP v1.5

14,080.45 USDC • CodeHawks • lanrebayode77

gold

Jun '24

Size

Size

6.17 USDC • 1 total finding • Code4rena • lanrebayode77

#58

medium

Fragmentation fee is not taken if user compensates with newly created position

May '24

Munchables

Munchables

0 USDC • 1 total finding • Code4rena • lanrebayode77

#17

high

Malicious User can call `lockOnBehalf` repeatedly extend a users `unlockTime`, removing their ability to withdraw previously locked tokens

Apr '24

Renzo

Renzo

0.04 USDC • 2 total findings • Code4rena • lanrebayode77

#57

high

Incorrect withdraw queue balance in TVL calculation

medium

Deposits will always revert if the amount being deposited is less than the bufferToFill value

NOYA

NOYA

0.02 USDC + NOYA stars • 1 total finding • Code4rena • lanrebayode77

#122

high

`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`

Panoptic

Panoptic

32.96 USDC • 1 total finding • Code4rena • lanrebayode77

#18

medium

removedLiquidity can be underflowed to lock other user's deposits

Mar '24

Taiko

Taiko

177.52 USDC • 1 total finding • Code4rena • lanrebayode77

#30

medium

retryMessage unable to handle edge cases.

Revert Lend

Revert Lend

1,398.31 USDC • 5 total findings • Code4rena • lanrebayode77

#8

medium

Asymmetric calculation of price difference

medium

dailyDebtIncreaseLimitLeft is not updated in liquidate().

medium

Repayments and liquidations can be forced to revert by an attacker that repays miniscule amount of shares

medium

Due to interest rates update method, Interest-Free Loans are possible and the Cost of DoS are reduced

medium

An attacker can easily bypass the collateral value limit factor checks

Feb '24

arcadexyz/arcade-protocol

arcadexyz/arcade-protocol

3,013.44 USDC • 1 total finding • Cantina • Lanrebayode77

#5

medium

Finding not yet public.

AI Arena

AI Arena

61.36 USDC • 3 total findings • Code4rena • lanrebayode77

#89

high

Since you can reroll with a different fighterType than the NFT you own, you can reroll bypassing maxRerollsAllowed and reroll attributes based on a different fighterType

medium

NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)

medium

Constraints of dailyAllowanceReplenishTime and allowanceRemaining during mint() can be bypassed by using alias accounts & safeTransferFrom()

Jan '24

Salty.IO

Salty.IO

47.36 USDC • 3 total findings • Code4rena • lanrebayode77

#91

high

When borrowers repay USDS, it is sent to the wrong address, allowing anyone to burn Protocol Owned Liquidity and build bad debt for USDS

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

medium

DOS of proposals by abusing ballot names without important parameters

reNFT

reNFT

25.02 USDC • Code4rena • lanrebayode77

#54

Nov '23

Panoptic

Panoptic

115.49 USDC • 1 total finding • Code4rena • lanrebayode77

#22

medium

removedLiquidity can be underflowed to lock other user's deposits

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

207.11 USDC • 1 total finding • Code4rena • lanrebayode77

#17

medium

Users will lose rewards when buying new tokens if they already own some tokens

Oct '23

NextGen

NextGen

2,850.09 USDC • 3 total findings • Code4rena • lanrebayode77

bronze

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

high

Adversary can block `claimAuction()` due to push-strategy to transfer assets to multiple bidders

medium

If an airdrop happens before a mint the price could skyrocket

Ethena Labs

Ethena Labs

123.66 USDC • 1 total finding • Code4rena • lanrebayode77

#26

medium

``FULL_RESTRICTED`` Stakers can bypass restriction through approvals

The Wildcat Protocol

The Wildcat Protocol

0.06 USDC • 1 total finding • Code4rena • lanrebayode77

#75

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

11.47 USDC • Code4rena • lanrebayode77

#60

Aug '23

Dopex

Dopex

17.39 USDC • 3 total findings • Code4rena • lanrebayode77

#111

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

high

The peg stability module can be compromised by forcing lowerDepeg to revert.

high

Users can get immediate profit when deposit and redeem in `PerpetualAtlanticVaultLP`

Shell Protocol

Shell Protocol

9.16 USDC • Code4rena • lanrebayode77

#19

veRWA

veRWA

22.7 USDC • 1 total finding • Code4rena • lanrebayode77

#48

high

Voters from VotingEscrow can vote infinite times in vote_for_gauge_weights() of GaugeController

Tangible Caviar

Tangible Caviar

6.87 USDC • Code4rena • lanrebayode77

#81

Jul '23

Moonwell

Moonwell

15.29 USDC • Code4rena • lanrebayode77

#38

PoolTogether

PoolTogether

15.92 USDC • Code4rena • lanrebayode77

#66

Jun '23

Lybra Finance

Lybra Finance

23.95 USDC • 2 total findings • Code4rena • lanrebayode77

#78

high

Incorrectly implemented modifiers in LybraConfigurator.sol allow any address to call functions that are supposed to be restricted

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called

May '23

Venus Protocol Isolated Pools

Venus Protocol Isolated Pools

1,807.4 USDC • 1 total finding • Code4rena • lanrebayode77

#9

medium

Fix utilization rate computation