https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/c73619fc-d2b1-458c-88bf-cfdad82b65e6.jpg

mahdikarimi

Security Researcher

Blockchain Security Researcher

Contact Me

High

2

Solo

30

Total

Medium

17

Total

$66.20K

Total Earnings

#126 All Time

32x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

bronze

2x

3rd Places

All

Sherlock

Code4rena

Cantina

Immunefi

Hats Finance

Apr '25

Aegis.im YUSD

Aegis.im YUSD

139.83 OP • 1 total finding • Sherlock • mahdikarimi

bronze

medium

Denial-of-Service via Instant Withdrawals to Exhaust Periodic Redeem Cap

Dec '24

juicebox-monorepo

juicebox-monorepo

5,232.48 OP • 3 total findings • Cantina • MehdiKarimi

silver

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

282.03 USDC • 3 total findings • Sherlock • mahdikarimi

#15

high

OverCalculation of marketFunds in buyVotes

high

Malicious users can pay less voucher fee

medium

Lack of slippage protection in sellVotes function

Aug '24

Proof Of Humanity V2

Proof Of Humanity V2

20,000 USDC • 2 total findings • Hats • MahdiKarimi

gold

high

DoS at process vouch fundion leads to loss of funds

high

Malicious user can DoS claim humanity at vouching state

Jul '24

MakerDAO Endgame

MakerDAO Endgame

382.81 USDC • Sherlock • mahdikarimi

#79

Jun '24

Inverter Network

Inverter Network

3,100 UMA • Hats • MahdiKarimi

#10

Apr '24

Audit Comp | Alchemix

Audit Comp | Alchemix

2,442 USDC • 5 total findings • Immunefi • MahdiKarimi

#11

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

Exactly Protocol

Exactly Protocol

992.73 USDC • 1 total finding • Sherlock • mahdikarimi

#8

medium

hanleBadDebt doesn't clear badDebt completely

Mar '24

Amphor

Amphor

194.58 USDC • 1 total finding • Sherlock • mahdikarimi

#11

high

claimDeposit function can lead to loss of pending deposit amount

Feb '24

Audit Comp | ZeroLend

Audit Comp | ZeroLend

24,697 USDC • 4 total findings • Immunefi • MahdiKarimi

bronze

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

Audit Comp | Puffer Finance

Audit Comp | Puffer Finance

1,699 USDC • 1 total finding • Immunefi • MahdiKarimi

#10

medium

Finding not yet public.

Napier

Napier

274.00 USDC • 1 total finding • Sherlock • mahdikarimi

#8

medium

Attacker can DoS redeeming of PT and YT tokens

Jan '24

Opus

Opus

940.83 USDC • Code4rena • mahdikarimi

#13

SYMM IO

SYMM IO

182.92 USDC • Sherlock • mahdikarimi

#10

Dec '23

Footium Update

Footium Update

217.83 USDC • Sherlock • mahdikarimi

#11

Ethereum Credit Guild

Ethereum Credit Guild

35.78 USDC • 1 total finding • Code4rena • mahdikarimi

#79

medium

Anyone can prolong the time for the rewards to get distributed

Oct '23

Party Protocol

Party Protocol

117.57 USDC • 1 total finding • Code4rena • mahdikarimi

#26

medium

PartyGovernanceNFT.sol#mint - User can delegate another user funds to themselves and brick them from changing the delegation

The Wildcat Protocol

The Wildcat Protocol

0 USDC • 1 total finding • Code4rena • mahdikarimi

#76

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

Sep '23

Ondo Finance

Ondo Finance

18.85 USDC • Code4rena • mahdikarimi

#29

Aug '23

Cooler Update

Cooler Update

171.61 USDC • 2 total findings • Sherlock • mahdikarimi

#12

high

when a loan defaults, lender can lost the unclaimed amount

medium

Lender can abuse borrower

Dopex

Dopex

648.93 USDC • 3 total findings • Code4rena • mahdikarimi

#32

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

high

Put settlement can be anticipated and lead to user losses and bonding DoS

high

Users can get immediate profit when deposit and redeem in `PerpetualAtlanticVaultLP`

Jul '23

Beam

Beam

234.18 USDC • Sherlock • mahdikarimi

#5

Jun '23

Lybra Finance

Lybra Finance

5.53 USDC • 1 total finding • Code4rena • mahdikarimi

#84

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called

May '23

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

185.91 USDC • 3 total findings • Sherlock • mahdikarimi

#13

high

Everyone can burn free tokens in USSD contract

high

Inflation attack to rebalance

medium

removed collateral can't be accessible

Apr '23

Teller

Teller

66.19 USDC • 2 total findings • Sherlock • mahdikarimi

#38

high

borrower escapes from depositing collateral

high

Lender makes unexpected commitment for borrower

Frankencoin

Frankencoin

2,537.21 USDC • 2 total findings • Code4rena • mahdikarimi

#5

high

When the challenge is successful, the user can send tokens to the position to avoid the position's cooldown period being extended

high

Challenges can be frontrun with de-leveraging to cause lossses for challengers

Feb '23

OlympusDAO

OlympusDAO

244.64 USDC • 2 total findings • Sherlock • mahdikarimi

#23

medium

adding new internal reward token can lock some functionalities

medium

freezing user rewards for a while

Carapace

Carapace

838.45 USDC • 3 total findings • Sherlock • mahdikarimi

#14

high

Malicious user can manipulate premeium price before buy protection

high

protection seller can withdraw funds before being locked in case of lending pool deafault

medium

buy protection doesn't assesses LendingPools status before verifyProtection

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

0.75 USDC • 1 total finding • Code4rena • mahdikarimi

#85

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`

Dec '22

Escher contest

Escher contest

1.76 USDC • 2 total findings • Code4rena • mahdikarimi

#67

high

`LPDA` price can underflow the price due to bad settings and potentially brick the contract

medium

ETH will get stuck if all NFTs do not get sold.

Nov '22

ParaSpace contest

ParaSpace contest

266.74 USDC • 1 total finding • Code4rena • mahdikarimi

#40

medium

Fallback oracle is using spot price in Uniswap liquidity pool, which is very vulnerable to flashloan price manipulation

Sep '22

QuickSwap and StellaSwap contest

QuickSwap and StellaSwap contest

52.04 USDC • Code4rena • mahdikarimi

#51