https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/76a082b0-4d3d-41bb-9327-3573a3e4e992.jpg

lil.eth

Security Researcher

smart contract lover

Contact Me

High

9

Total

Medium

17

Total

$2.75K

Total Earnings

#962 All Time

15x

Payouts

regular

2x

Top 10

regular

10x

Top 25

regular

14x

Top 50

All

Sherlock

Feb '24

Rio Network

Rio Network

5.57 USDC • 1 total finding • Sherlock • lil.eth

#31

high

Aggregate Root could Mismatch in Withdrawal Processing

Jan '24

LooksRare YOLO

LooksRare YOLO

87.39 USDC • 1 total finding • Sherlock • lil.eth

#6

medium

MAXIMUM_NUMBER_OF_DEPOSITS_PER_ROUND can be bypassed in certain conditions

Dec '23

Olympus RBS 2.0

Olympus RBS 2.0

293.90 USDC • 1 total finding • Sherlock • lil.eth

#16

medium

Inconsistency in BunniToken Price Calculation

Nov '23

Convergence

Convergence

559.66 USDC • 1 total finding • Sherlock • lil.eth

#11

medium

Delegation Limitation in Voting Power Management

Oct '23

LooksRare

LooksRare

166.38 USDC • 1 total finding • Sherlock • lil.eth

#8

medium

Game is not fair if less round passed than 2 and agents pass under the threshold of 50 users

Real Wagmi #2

Real Wagmi #2

211.82 USDC • 2 total findings • Sherlock • lil.eth

#15

high

_restoreLiquidity() is extemely easy to manipulate due to how it calculates underlying token balances

medium

Underflow in borrow() Function

Sep '23

Allo V2

Allo V2

68.90 USDC • 4 total findings • Sherlock • lil.eth

#45

high

Missing Allocator Voice Credit Incrementation in QV Strategy _allocate()

medium

FEE-ON-TRANSFER usage could DOS a pool

medium

QVStrategy : Funds locked if no registered recipient or no recipientStatus >= reviewThreshold

medium

Exponential Inflation of Voice Credits in Quadratic Voting Strategy

Jul '23

Tokemak

Tokemak

78.14 USDC • 2 total findings • Sherlock • lil.eth

#46

high

Incorrect Accounting of newRewards in the queueNewRewards() function of AbstractRewarder Contract

high

Missing token transfer between LiquidationRow.sol and BaseAsyncSwapper.sol during liquidation of Vaults For Token

Bond Options

Bond Options

103.21 USDC • 1 total finding • Sherlock • lil.eth

#16

medium

Creation of Options At Expiry Time Can Lead to Loss of Funds

Jun '23

Hubble Exchange

Hubble Exchange

847.32 USDC • 4 total findings • Sherlock • lil.eth

#12

medium

Small depositors might receive zero shares due to integer division in depositFor function

medium

Chainlink’s latestRoundData might return stale or incorrect results

medium

Oracle.sol Assume that stablecoin Price is stable

medium

min withdraw of 5 VUSD is not enough to prevent DOS via VUSD.sol#withdraw(amount)

RealWagmi

RealWagmi

25.44 USDC • 1 total finding • Sherlock • lil.eth

#22

medium

Rounding Errors in the _getTicksForPosition()

May '23

Iron Bank

Iron Bank

0.00 USDC • 1 total finding • Sherlock • lil.eth

#25

medium

Chainlink's latestRoundData might return stale or incorrect results

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

0.00 USDC • 4 total findings • Sherlock • lil.eth

#94

high

Misconfigured Price Feed Aggregator

high

Unrestricted Minting and Burning Functions

high

Unchecked Slippage Vulnerability in USSD Contract

medium

Stale or Outdated Price in getPriceUSD() Function in StableOracle Contracts

Index

Index

0.17 USDC • 1 total finding • Sherlock • lil.eth

#25

medium

Use of Deprecated ChainLink function : latestAnswer()

Apr '23

JOJO Exchange

JOJO Exchange

301.11 USDC • 1 total finding • Sherlock • lil.eth

#28

high

Front-Running Vulnerability in depositStableCoin() Function