https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

reassor

Security Researcher

Contact Me

High

7

Total

Medium

34

Total

$19.00K

Total Earnings

#411 All Time

35x

Payouts

bronze

1x

3rd Places

regular

5x

Top 10

regular

20x

Top 25

All

Sherlock

Code4rena

Mar '23

Asymmetry contest

Asymmetry contest

286.82 USDC • 2 total findings • Code4rena • reassor

#23

high

Price of sfrxEth derivative is calculated incorrectly

medium

DoS due to external call failure

Canto Identity Subprotocols contest

Canto Identity Subprotocols contest

128.33 USDC • 2 total findings • Code4rena • reassor

#18

medium

Users can end up buying and paying for a different Tray than the one they were trying to acquire

medium

Bio Protocol - `tokenURI` JSON injection

Dec '22

Escher contest

Escher contest

51.79 USDC • 3 total findings • Code4rena • reassor

#49

high

`LPDA` price can underflow the price due to bad settings and potentially brick the contract

high

`saleReceiver` and `feeReceiver` can steal refunds after sale has ended

medium

ETH will get stuck if all NFTs do not get sold.

Nov '22

Opyn Crab Netting

Opyn Crab Netting

148.20 USDC • 2 total findings • Sherlock • reassor

#17

high

Denial of Service of depositAuction and withdrawAuction

medium

Denial of Service - userDepositIndex and userWithdrawIndex growing indefinitely

Sep '22

QuickSwap and StellaSwap contest

QuickSwap and StellaSwap contest

52.21 USDC • Code4rena • reassor

#49

VTVL contest

VTVL contest

19.6 USDC • 1 total finding • Code4rena • reassor

#74

medium

Supply cap of VariableSupplyERC20Token is not properly enforced

Aug '22

Olympus DAO contest

Olympus DAO contest

2,324.37 USDC • 3 total findings • Code4rena • reassor

#9

medium

OlympusGovernance - active proposal does not expire

medium

Inconsistency in staleness checks between OHM and reserve token oracles

medium

[NAZ-M1] Chainlink's `latestRoundData` Might Return Stale Results

FIAT DAO veFDT contest

FIAT DAO veFDT contest

577.06 USDC • 2 total findings • Code4rena • reassor

#7

medium

Unsafe casting from int128 can cause wrong accounting of locked amounts

medium

Attacker contract can avoid being blocked by BlockList.sol

Fraxlend (Frax Finance) contest

Fraxlend (Frax Finance) contest

326.47 USDC • 1 total finding • Code4rena • reassor

#16

medium

FraxlendPair#setTimeLock: Allows the owner to reset TIME_LOCK_ADDRESS

Jul '22

Golom contest

Golom contest

325.18 USDC • Code4rena • reassor

#37

Yield Witch v2 contest

Yield Witch v2 contest

39.13 USDC • Code4rena • reassor

#40

Fractional v2 contest

Fractional v2 contest

4.96 USDC • 1 total finding • Code4rena • reassor

#102

medium

Delegate call in `Vault#_execute` can alter Vault's ownership

Jun '22

Putty contest

Putty contest

920.96 USDC • 1 total finding • Code4rena • reassor

#17

medium

Overlap Between `ERC721.transferFrom()` and `ERC20.transferFrom()` Allows `order.erc20Assets` or `order.baseAsset` To Be ERC721 Rather Than ERC20

Nibbl contest

Nibbl contest

2,424.37 USDC • 1 total finding • Code4rena • reassor

bronze

medium

NibblVault buyout duration longer than update timelock

Yieldy contest

Yieldy contest

119.21 USDC • Code4rena • reassor

#41

Badger-Vested-Aura contest

Badger-Vested-Aura contest

188.08 USDC • Code4rena • reassor

#15

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

201.29 USDC • 1 total finding • Code4rena • reassor

#33

medium

Protocol fee rate can be arbitrarily modified by the owner and the new rate will apply to all existing orders

May '22

veToken Finance contest

veToken Finance contest

544.82 USDT • Code4rena • reassor

#28

Velodrome Finance contest

Velodrome Finance contest

133.19 USDC • Code4rena • reassor

#44

Rubicon contest

Rubicon contest

175.07 USDC • 2 total findings • Code4rena • reassor

#41

high

BathToken LPs Unable To Receive Bonus Token Due To Lack Of Wallet Setter Method

medium

No cap on fees can result in a DOS in BathToken.withdraw()

Aura Finance contest

Aura Finance contest

682.04 USDC • Code4rena • reassor

#16

Cally contest

Cally contest

96.33 USDC • 2 total findings • Code4rena • reassor

#38

medium

Owner can modify the feeRate on existing vaults and steal the strike value on exercise

medium

Vault is Not Compatible with Fee Tokens and Vaults with Such Tokens Could Be Exploited

FactoryDAO contest

FactoryDAO contest

680.69 DAI • 4 total findings • Code4rena • reassor

#12

high

SpeedBumpPriceGate: Excess ether did not return to the user

medium

amount requires to be updated to contract balance increase (1)

medium

ERC20 tokens with different decimals than 18 leads to loss of funds

medium

Centralisation Risk: Owner may abuse the tax rate to claim 99.9% of pools

Cudos contest

Cudos contest

651.51 USDC • 1 total finding • Code4rena • reassor

#19

medium

Protocol doesn't handle fee on transfer tokens

Forgotten Runes Warrior Guild contest

Forgotten Runes Warrior Guild contest

515.73 USDC • 2 total findings • Code4rena • reassor

#20

medium

Use of `.send()` May Revert if The Recipient's Fallback Function Consumes More Than 2300 Gas

medium

Many unbounded and under-constrained variables in the system can lead to unfair price or DoS

Apr '22

PoolTogether Aave v3 contest

PoolTogether Aave v3 contest

377.45 USDC • 1 total finding • Code4rena • reassor

#13

medium

_depositAmount requires to be updated to contract balance increase

AbraNFT contest

AbraNFT contest

232.66 MIM • Code4rena • reassor

#22

Backd contest

Backd contest

351.93 USDC • 2 total findings • Code4rena • reassor

#26

medium

_revokeRole doesn't remove account from roleMember set

medium

Chainlink's latestRoundData might return stale or incorrect results

Phuture Finance contest

Phuture Finance contest

22.05 USDC • 1 total finding • Code4rena • reassor

#35

medium

Chainlink's latestRoundData might return stale or incorrect results

Badger Citadel contest

Badger Citadel contest

2,832.74 USDC • 2 total findings • Code4rena • reassor

#10

high

StakedCitadel: wrong setupVesting function name

medium

KnightingRound tokenOutPrice changes

JPEG'd contest

JPEG'd contest

177.29 USDC • 1 total finding • Code4rena • reassor

#40

medium

Chainlink pricer is using a deprecated API

Duality Focus contest

Duality Focus contest

78.24 USDC • Code4rena • reassor

#14

Backed Protocol contest

Backed Protocol contest

102.04 USDC • Code4rena • reassor

#25

Mar '22

Paladin contest

Paladin contest

2,674.53 USDC • 1 total finding • Code4rena • reassor

#6

medium

Emergency mode enable/disable issue

Feb '22

Concur Finance contest

Concur Finance contest

538.97 USDC • 2 total findings • Code4rena • reassor

#22

medium

Donated Tokens Cannot Be Recovered If A Shelter Is Deactivated

medium

[ConcurRewardPool] Possible reentrancy when claiming rewards