https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/b7d6267e-c88b-40c9-80c5-92cf2aa14d0a.jpg

n33k

Security Researcher

security researcher

Contact Me

High

18

Total

Medium

1

Solo

11

Total

$28.47K

Total Earnings

#283 All Time

16x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

8x

Top 10

All

Sherlock

Code4rena

Aug '23

Good Entry

Good Entry

250.17 USDC • 1 total finding • Code4rena • n33k

#20

medium

First depositor can break minting of liquidity shares in GeVault

Jul '23

Perennial V2

Perennial V2

1,365.53 USDC • 1 total finding • Sherlock • n33k

#8

medium

Market: DoS when stuffed with pending protected positions

Tokensoft

Tokensoft

78.59 USDC • 1 total finding • Sherlock • n33k

#14

medium

CrosschainDistributor: Not paying relayer fee when calling xcall to claim tokens to other domains

Tokemak

Tokemak

1,089.99 USDC • 3 total findings • Sherlock • n33k

#20

high

LMPVaultRouterBase: Native ETH lost in router when mint&deposit

high

LMPVault: Wrong accounting because of unsynced `totalDebt`

medium

LMPVault: DoS when `feeSink` balance hits `perWalletLimit`

Jun '23

GLIF

GLIF

3,280.19 USDC • Sherlock • n33k

#4

Findings not publicly available for private contests.

Unstoppable

Unstoppable

1,600.25 USDC • 5 total findings • Sherlock • n33k

#5

high

Vault: The attacker can sandwich attack himself on swaps in open_position, close_position and reduce_position to make a bad debt

high

Vault: reduced margin is not added back to account

high

Vault: position margin should be valued in postion token but not debt token

high

Vault: `_update_debt` does not accrue interest

medium

Vault: 24h ORACLE_FRESHNESS_THRESHOLD is too long for oracle price freshness check

RealWagmi

RealWagmi

2,763.39 USDC • 2 total findings • Sherlock • n33k

bronze

high

`rebalanceAll` won't work if the fee 500 uniswap pool is not added

high

Liquidity adding in `rebalanceAll` is vulnerable to sandwich attack

Arrakis

Arrakis

14,032.98 USDC • 2 total findings • Sherlock • n33k

silver

high

Operator can hijack rebalance control flow inside `swap.router.call` to manipulate pool prices and sandwich attack subsequent liquidity minting

medium

Operator rebalance should be rate limited

Unitas Protocol

Unitas Protocol

1,409.13 USDC • 1 total finding • Sherlock • n33k

#8

high

MEV bot can sandwich attack oracle update transactions to steal the protocol

May '23

Iron Bank

Iron Bank

0.03 USDC • 2 total findings • Sherlock • n33k

#23

medium

Missing check for whether L2 Sequencer is active

medium

Oracle has no check for round completeness

Eco Protocol

Eco Protocol

571.13 USDC • 1 total finding • Sherlock • n33k

bronze

high

Stale inflationMultiplier in L1ECOBridge

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

200.97 USDC • 5 total findings • Sherlock • n33k

#10

high

mintRebalancer missing onlyBalancer

high

UniV3SwapInput is vulnerable to sandwich attack

high

getOwnValuation is vulnerable to price manipulation attack

high

getSupplyProportion uses Uniswap V3 pool token balances which can be easily manipulated

high

Wrong price decimal handling in StableOracleDAI

Index

Index

219.60 USDC • 1 total finding • Sherlock • n33k

#15

medium

invokeApprove should approve 0 first

Apr '23

Teller

Teller

0.95 USDC • 1 total finding • Sherlock • n33k

#51

medium

FEE-ON-TRANSFER tokens can not be used as collateral

Mar '23

Asymmetry contest

Asymmetry contest

21.17 USDC • 2 total findings • Code4rena • n33k

#102

high

An attacker can manipulate the preDepositvePrice to steal from other users.

medium

Residual ETH unreachable and unuitilized in SafEth.sol

Feb '23

GMX

GMX

1,585.08 USDC • 1 total finding • Sherlock • n33k

#16

high

WNT in depositVault can be drained by abusing initialLongToken/initialShortToken of CreateDepositParams