https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/383d09fb-073b-4066-8cf7-81b1566ae369.jpg

m4k2

Security Researcher

Learning web3 security || CTF || Building @BeyondBZH

Contact Me

High

10

Total

Medium

13

Total

$3.19K

Total Earnings

#878 All Time

9x

Payouts

gold

1x

1st Places

regular

2x

Top 10

regular

5x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Dec '24

SecondSwap

SecondSwap

4.28 USDC • 2 total findings • Code4rena • m4k2

#54

high

Users can claim more that their actual allotment

medium

Creator of one vesting plan can affect vesting plans created by other users.

Lambo.win

Lambo.win

388.43 USDC • 5 total findings • Code4rena • m4k2

#7

high

LamboFactory can be permanently DoS-ed due to createPair call reversal

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

medium

Since the cost of launching a new pool is minimal, an attacker can maliciously consume VirtualTokens.

medium

Accumulated ETH in the LamboVEthRouter will be irretrievable

medium

Attacker can captures `VETH-WETH` depeg profits through a malicious pool, rendering rebalancer useless if VETH Price > WETH Price

Nov '24

vVv Launchpad - Investments & Token distribution

vVv Launchpad - Investments & Token distribution

94.59 USDC • 1 total finding • Sherlock • m4k2

gold

high

MEV Bots Can Front-Run Token Claims Due to Missing Sender Validation

Oct '24

Dria

Dria

98.47 USDC • 7 total findings • CodeHawks • m4k2xmk

#15

high

Subtraction in `variance()` will revert due to underflow

high

Potential underflow vulnerability in score range calculation of `LLMOracleCoordinator::finalizeValidation`, leading to DoS.

medium

Request responses and validations can be mocked leading to extraction of fees and/or forcing other generators to lose their fees by making them outliers

medium

Unrestricted validation score range for validators in `LLMOracleCoordinator::validate`.

medium

Users can list assets with price < 1 ERC20 (ETH, WETH), leading to potential DoS vulnerability.

low

Inaccurate best response selection in `LLMOracleCoordinator::getBestResponse`.

low

Inconsistent Best Response Selection Due to Missing Tiebreak Mechanism

Aug '24

Chakra

Chakra

39.54 USDT • 1 total finding • Code4rena • m4k2

#42

medium

Excessive Authority Granted to Managers in the `ckr_btc.cairo` Contract Presents Significant Management Risks

zetachain-protocol

zetachain-protocol

214.68 USDC • 3 total findings • Cantina • m4k2

#41

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

ArkProject: NFT Bridge

ArkProject: NFT Bridge

413.64 USDC • 3 total findings • CodeHawks • m4k2xmk

#21

high

`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`

high

The Bridging Process will revert if the Collection is matched on the destination chain and not matched on the source chain

medium

There is No `msg.value` check in `depositTokens`, causing potential token stuck

Jun '24

Size

Size

1,903.96 USDC • 2 total findings • Code4rena • m4k2

#16

high

When `sellCreditMarket()` is called to sell credit for a specific cash amount, the protocol might receive a lower swapping fee than expected.

high

The collateral remainder cap is incorrectly calculated during liquidation

Oct '23

Open Dollar

Open Dollar

30.3 USDC • 1 total finding • Code4rena • m4k2

#49

medium

`ODSafeManager#allowSAFE()` cannot be executed either by the proxy contract or any other address.