https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

p4st13r4

Security Researcher

Contact Me

High

8

Total

Medium

10

Total

$12.59K

Total Earnings

#504 All Time

26x

Payouts

regular

2x

Top 10

regular

16x

Top 25

regular

24x

Top 50

All

Code4rena

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

18.7 USDC • 1 total finding • Code4rena • p4st13r4

#72

medium

DOS risk if enough tokens are minted in Quest.claim can lead, at least, to transaction fee lost

Oct '22

3xcalibur contest

3xcalibur contest

0 USDC • Code4rena • p4st13r4

#39

Jun '22

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

276.92 USDC • 1 total finding • Code4rena • p4st13r4

#29

high

Calling `unstake()` can cause locked funds

Canto contest

Canto contest

3,134.46 USDC • 5 total findings • Code4rena • p4st13r4

#10

high

`lending-market/Note.sol` Wrong implementation of access control

high

WETH.sol computes the wrong totalSupply()

high

Transferring any amount of the underlying token to the CNote contract will make the contract functions unusable

high

Anyone can create Proposal Unigov Proposal-Store.sol

medium

In Cnote.sol, anyone can initially become both accountant and admin

May '22

Sturdy contest

Sturdy contest

69.55 USDC • 1 total finding • Code4rena • p4st13r4

#33

high

The check for value transfer success is made after the return statement in _withdrawFromYieldPool of LidoVault

Cally contest

Cally contest

621.88 USDC • 1 total finding • Code4rena • p4st13r4

#17

medium

It shouldn’t be possible to create a vault with Cally’ own token

Enso Finance contest

Enso Finance contest

1,656.23 USDT • Code4rena • p4st13r4

#15

FactoryDAO contest

FactoryDAO contest

3.18 DAI • 1 total finding • Code4rena • p4st13r4

#62

medium

amount requires to be updated to contract balance increase (1)

Forgotten Runes Warrior Guild contest

Forgotten Runes Warrior Guild contest

94.43 USDC • 1 total finding • Code4rena • p4st13r4

#36

medium

Use of `.send()` May Revert if The Recipient's Fallback Function Consumes More Than 2300 Gas

Feb '22

Redacted Cartel contest

Redacted Cartel contest

61.98 USDC • Code4rena • p4st13r4

#32

Badger Citadel contest

Badger Citadel contest

515.78 USDC • 1 total finding • Code4rena • p4st13r4

#17

medium

Seven ways in which the Owner and Proxy Admin can make users lose funds ("rug vectors")

Jan '22

OpenLeverage contest

OpenLeverage contest

14.21 USDT • Code4rena • p4st13r4

#21

Behodler contest

Behodler contest

25.7 USDC • Code4rena • p4st13r4

#29

Trader Joe contest

Trader Joe contest

735.25 USDT • 1 total finding • Code4rena • p4st13r4

#19

medium

`createRJLaunchEvent()` can be called by anyone with 1 Wei of `_token` and stop others from creating RJLaunchEvent with the same token anymore

Sherlock contest

Sherlock contest

37.91 USDC • Code4rena • p4st13r4

#27

ElasticSwap contest

ElasticSwap contest

47.94 USDC • Code4rena • p4st13r4

#16

Livepeer contest

Livepeer contest

13.91 tokens) • Code4rena • p4st13r4

#22

InsureDAO contest

InsureDAO contest

3,184.57 tokens) • 2 total findings • Code4rena • p4st13r4

#7

high

Typo in PoolTemplate unlock function results in user being able to unlock multiple times

medium

repayDebt in Vault.sol could DOS functionality for markets

Sandclock contest

Sandclock contest

174.87 USDC • Code4rena • p4st13r4

#24

XDEFI contest

XDEFI contest

4.79 USDC • Code4rena • p4st13r4

#32

Timeswap contest

Timeswap contest

260.69 USDC • Code4rena • p4st13r4

#17

Dec '21

Vader Protocol contest

Vader Protocol contest

83.25 USDC • Code4rena • p4st13r4

#15

Yeti Finance contest

Yeti Finance contest

256.72 USDC • Code4rena • p4st13r4

#20

NFTX contest

NFTX contest

522.3 USDC • 1 total finding • Code4rena • p4st13r4

#18

high

A vault can be locked from MarketplaceZap and StakingZap

Amun contest

Amun contest

739.46 USDC • 2 total findings • Code4rena • p4st13r4

#17

medium

ERC20 return values not checked

medium

Function `joinTokenSingle` in `SingleTokenJoin.sol` and `SingleTokenJoinV2.sol` can be made to fail

Sublime contest

Sublime contest

37.57 USDC • Code4rena • p4st13r4

#18