Security Researcher
trying to make web3 more secure Security research portfolio: https://github.com/utkuerkin/Security-Research-Findings
High
Total
Medium
Total
Total Earnings
#566 All Time
Payouts
1st Places
2nd Places
3rd Places
All
Sherlock
Code4rena
CodeHawks
Nov '24
Oct '24
Apr '24
high
Attacker can make 0 value deposit() calls to deny user from redeeming or withdrawing collateral
high
Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine
high
Kerosene collateral is not being moved on liquidation, exposing liquidators to loss
high
Unable to withdraw Kerosene from `vaultmanagerv2::withdraw` as it expects a `vault.oracle()` method which is missing in Kerosene vaults
medium
`VaultManagerV2.sol::burnDyad` function is missing an `isDNftOwner` modifier, allowing a user to burn another user's minted DYAD
medium
Attacker can frontrun to prevent vaults from being removed from the dNFT owner's position
medium
Liquidating positions with bounded Kerosen could be unprofitable for liquidators
Mar '24
Jan '24
Dec '23
Jul '23