Security Researcher
Independent Security Researcher | Ex-ISRO | Ex- Income Tax Department | Serving in the Ministry of Defence 1f0f349fd6
High
Total
Medium
Total
Total Earnings
#449 All Time
Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Jan '25
Findings not publicly available for private contests.
Dec '24
Findings not publicly available for private contests.
Oct '24
Findings not publicly available for private contests.
Findings not publicly available for private contests.
Sep '24
medium
medium
Aug '24
high
medium
medium
medium
medium
Functions in superPool do not check if the pool is paused
medium
`redeem` and `withdraw` do not include slippage protection
medium
`SuperPool` is ERC-4626 compliant, but the `maxWithdraw` & `maxRedeem` functions are not fully up to EIP-4626's specification
medium
No incentive to liquidate small position can lead to bad debts
Jul '24
Jun '24
87.93 USDC • 1 total finding • Sherlock • pseudoArtist
#13
May '24
medium
incorrect price for negative ticks due to lack of rounding down
medium
`updateIRMParams` does not call `applyInterestForToken` before updating `irmParams` which leads to incorrect calculation of interest rate for subsequent trades.
medium
Liquidity manipulation is possible when trading
medium
Vaults can become immune from liquidation by setting `vault.recipient` to a blacklisted quote token address
medium
Chainlink's `latestRoundData` might return stale or incorrect results
Apr '24
high
`PendleConnector` incorrectly sends the redeemed `PT` tokens to the market instead of the
high
`executeWithdraw` may be blocked if any of the users are blacklisted from the `baseToken`
high
Numerous errors when calculating the TVL for the MorphoBlue connector
high
In Dolomite, when opening a borrow position, the holding position in the Registry will never be updated due to the removePosition flag being set to true
medium
LP tokens from Boosted Positions are not included in the TVL calculation of a position held by the MaverickConnector
medium
Withdrawals in AccountManager are prone to DOS attacks.
medium
The total deposit amount limit in `AccountingManager.sol` can be bypassed
medium
Missing calls to `_updateTokenInRegistry` leads to incorrect state of tokens in registry
medium
Incorrect modifier condition
medium
`AccountingManager` contract's `previewDeposit`, `previewMint`, `previewWithdraw`, and `previewRedeem` functions are not compliant with EIP-4626 standard
medium
Extra rewards are not updated in curve connector when harvestConvexRewards is called
medium
Camelot and Aerodrome Connector TVL susceptible to manipulation attack
medium
Using the same heartbeat for multiple price feeds
Mar '24
Feb '24
Oct '23
Sep '23
Aug '23
Jul '23