https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

max10afternoon

Security Researcher

Contact Me

High

15

Total

Medium

10

Total

$7.09K

Total Earnings

#763 All Time

17x

Payouts

silver

1x

2nd Places

regular

3x

Top 10

regular

6x

Top 25

All

Code4rena

Oct '25

Reflector V3

Reflector V3

0.33 USDC • 1 total finding • Code4rena • max10afternoon

#14

medium

Systematic Overcharge in prices and x_prices: Fee Charged for Requested Records While Return is Capped at 20

Aug '25

GTE Perps and Launchpad

GTE Perps and Launchpad

43.82 USDC • 5 total findings • Code4rena • max10afternoon

#82

high

Total reward shares for token can reach zero after unlocking, causing `GTELaunchpadV2Pair` to be bricked

high

Donations to `Distributor` with arbitrary `quoteToken` can be used to drain all quote rewards from distributor

high

Attacker can drain funds from `GTELaunchPadV2Pair` using `swap`

high

CREATE2 address of the uniswap pair used by `LaunchPad` does not match address of pair deployed by `GTELaunchpadV2PairFactory`

medium

`LaunchToken` transfers cause staking rewards to be lost to the `LaunchPad`

Jun '24

Size

Size

0.05 USDC • 1 total finding • Code4rena • max10afternoon

#62

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

3,542.49 USDC • 4 total findings • Code4rena • max10afternoon

silver

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

medium

Malicious users can prevent holders from claiming their rewards during a reward cycle by skipping it.

medium

`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.

medium

Distribution can be bricked, and double claims by a few holders are possible when owner calls `LiquidInfrastructureERC20::setDistributableERC20s`

Nov '23

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

5.45 USDC • 1 total finding • Code4rena • max10afternoon

#29

medium

No slippage protection for Market functions

Kelp DAO | rsETH

Kelp DAO | rsETH

223.02 USDC • 3 total findings • Code4rena • max10afternoon

#18

high

The price of rsEHT could be manipulated by the first staker

high

Protocol mints less rsETH on deposit than intended

medium

Lack of slippage control on LRTDepositPool.depositAsset

Oct '23

NextGen

NextGen

0 USDC • 1 total finding • Code4rena • max10afternoon

#115

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

Ethena Labs

Ethena Labs

4.52 USDC • Code4rena • max10afternoon

#40

The Wildcat Protocol

The Wildcat Protocol

6.68 USDC • 2 total findings • Code4rena • max10afternoon

#70

high

Lenders can escape the blacklisting of their accounts because they can move their MarketTokens to different accounts and gain the WithdrawOnly Role on any account they want

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

zkSync Era

zkSync Era

273.57 USDC • Code4rena • max10afternoon

#35

Aug '23

Dopex

Dopex

17.47 USDC • 3 total findings • Code4rena • max10afternoon

#110

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

high

The peg stability module can be compromised by forcing lowerDepeg to revert.

high

Users can get immediate profit when deposit and redeem in `PerpetualAtlanticVaultLP`

Tangible Caviar

Tangible Caviar

0.03 USDC • Code4rena • max10afternoon

#87

Jul '23

Basin

Basin

17.52 USDC • Code4rena • max10afternoon

#26

Jun '23

Lybra Finance

Lybra Finance

1,652.48 USDC • 3 total findings • Code4rena • max10afternoon

#8

medium

Lack of timelock on rigidRedemption, enables to steal yield from other users

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called

medium

Exploiter can avoid negative Lido rebases stealing funds from EUSD vaults

Canto

Canto

19.36 USDC • Code4rena • max10afternoon

#12

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

333.3 USDC • 1 total finding • Code4rena • max10afternoon

#47

high

Rerange/rebalance should not use protocolFee as asset for adding liquidity

Juicebox Buyback Delegate

Juicebox Buyback Delegate

952.18 USDC • Code4rena • max10afternoon

#6