https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

mert_eren

Security Researcher

Contact Me

High

1

Solo

20

Total

Medium

11

Total

$20.43K

Total Earnings

#358 All Time

21x

Payouts

silver

2x

2nd Places

regular

6x

Top 10

regular

12x

Top 25

All

Sherlock

Code4rena

Jan '24

LooksRare YOLO

LooksRare YOLO

4,529.17 USDC • 2 total findings • Sherlock • mert_eren

silver

high

ERC-20 tokens can be used like ERC-721

high

with depositETHIntoMultipleRounds can deposit 0 eth to rounds and it can effect the winner of round

Oct '23

Ethena Labs

Ethena Labs

639.56 USDC • 2 total findings • Code4rena • mert_eren

#10

medium

``FULL_RESTRICTED`` Stakers can bypass restriction through approvals

medium

Malicious users can front-run to cause a denial of service (DoS) for StakedUSDe due to MinShares checks

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

11.58 USDC • 1 total finding • Code4rena • mert_eren

#59

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

Centrifuge

Centrifuge

857.31 USDC • 1 total finding • Code4rena • mert_eren

#17

medium

onlyCentrifugeChainOrigin() can't require msg.sender equal axelarGateway

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

5,525.65 USDC • Code4rena • mert_eren

#9

Cooler Update

Cooler Update

1,216.63 USDC • 2 total findings • Sherlock • mert_eren

#5

high

Borrower cannot repay if lender prevent it

high

Exploitable Vulnerability in Clearinghouse Contract's Reward Mechanism

Dopex

Dopex

64.27 USDC • 3 total findings • Code4rena • mert_eren

#89

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

medium

Inaccurate swap amount calculation in ReLP leads to stuck tokens and lost liquidity

medium

reLP() mintokenAAmount the calculations are wrong.

Shell Protocol

Shell Protocol

1,933.59 USDC • 1 total finding • Code4rena • mert_eren

#7

high

Lack of Balance Validation

Blueberry Update #3

Blueberry Update #3

2,209.91 USDC • 1 total finding • Sherlock • mert_eren

silver

high

wrong bToken's exchangeRateStored used for calculate ColleteralValue

veRWA

veRWA

300.89 USDC • 4 total findings • Code4rena • mert_eren

#13

high

Delegated votes are locked when owner lock is expired

high

Voters from VotingEscrow can vote infinite times in vote_for_gauge_weights() of GaugeController

high

User don't have to deposit for a week into the market to get his weekly reward from the `LendingLedger`

high

If governance removes a gauge, user's voting power for that gauge will be lost.

Tangible Caviar

Tangible Caviar

1,106.39 USDC • Code4rena • mert_eren

#14

Jul '23

Moonwell

Moonwell

943.23 USDC • 1 total finding • Code4rena • mert_eren

#11

medium

malicious `emissionToken` could poison rewards for a market

Amphora Protocol

Amphora Protocol

113.02 USDC • 1 total finding • Code4rena • mert_eren

#18

high

Rounding error in `WUSDA` can result in loss of user funds, especially when manipulated by an attacker

Mar '23

Gitcoin

Gitcoin

23.86 USDC • Sherlock • mert_eren

#61

Asymmetry contest

Asymmetry contest

3.49 USDC • 1 total finding • Code4rena • mert_eren

#123

high

An attacker can manipulate the preDepositvePrice to steal from other users.

Feb '23

Carapace

Carapace

89.34 USDC • 2 total findings • Sherlock • mert_eren

#31

high

Can withdraw money before it supposed to do

medium

If underlyingtoken=0 after lock capital there is no chance for deposit token due to function try division 0.

Jan '23

Popcorn contest

Popcorn contest

170.01 USDC • 3 total findings • Code4rena • mert_eren

#57

high

Staking rewards can be drained

high

Incorrect Reward Duration After Change in Reward Speed in MultiRewardStaking

high

Modifier VaultController._verifyCreatorOrOwner does not work as intented

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

145.31 USDC • 3 total findings • Code4rena • mert_eren

#29

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`

medium

Funds can be stuck due to wrong order of operations

medium

User may loose rewards if the receipt is minted after quest end time

Timeswap contest

Timeswap contest

278.1 USDC • 1 total finding • Code4rena • mert_eren

#16

medium

Fee on transfer tokens will not behave as expected

Dec '22

GoGoPool contest

GoGoPool contest

59.44 USDC • 1 total finding • Code4rena • mert_eren

#67

medium

Cancellation of minipool may skip MinipoolCancelMoratoriumSeconds checking if it was cancelled before

prePO contest

prePO contest

210.78 USDC • 1 total finding • Code4rena • mert_eren

#26

high

A whale user is able to cause freeze of funds of other users by bypassing withdraw limit