Security Researcher
High
Total
Medium
Total Earnings
#379 All Time
Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Mar '23
286.82 USDC • 2 total findings • Code4rena • reassor
#23
high
Price of sfrxEth derivative is calculated incorrectly
medium
DoS due to external call failure
128.33 USDC • 2 total findings • Code4rena • reassor
#18
Users can end up buying and paying for a different Tray than the one they were trying to acquire
Bio Protocol - `tokenURI` JSON injection
Dec '22
51.79 USDC • 3 total findings • Code4rena • reassor
#49
`LPDA` price can underflow the price due to bad settings and potentially brick the contract
`saleReceiver` and `feeReceiver` can steal refunds after sale has ended
ETH will get stuck if all NFTs do not get sold.
Nov '22
148.20 USDC • 2 total findings • Sherlock • reassor
#17
Denial of Service of depositAuction and withdrawAuction
Denial of Service - userDepositIndex and userWithdrawIndex growing indefinitely
Sep '22
52.21 USDC • Code4rena • reassor
19.6 USDC • 1 total finding • Code4rena • reassor
#74
Supply cap of VariableSupplyERC20Token is not properly enforced
Aug '22
2,324.37 USDC • 3 total findings • Code4rena • reassor
#9
OlympusGovernance - active proposal does not expire
Inconsistency in staleness checks between OHM and reserve token oracles
[NAZ-M1] Chainlink's `latestRoundData` Might Return Stale Results
577.06 USDC • 2 total findings • Code4rena • reassor
#7
Unsafe casting from int128 can cause wrong accounting of locked amounts
Attacker contract can avoid being blocked by BlockList.sol
326.47 USDC • 1 total finding • Code4rena • reassor
#16
FraxlendPair#setTimeLock: Allows the owner to reset TIME_LOCK_ADDRESS
Jul '22
325.18 USDC • Code4rena • reassor
#37
39.13 USDC • Code4rena • reassor
#40
4.96 USDC • 1 total finding • Code4rena • reassor
#102
Delegate call in `Vault#_execute` can alter Vault's ownership
Jun '22
920.96 USDC • 1 total finding • Code4rena • reassor
Overlap Between `ERC721.transferFrom()` and `ERC20.transferFrom()` Allows `order.erc20Assets` or `order.baseAsset` To Be ERC721 Rather Than ERC20
2,424.37 USDC • 1 total finding • Code4rena • reassor
NibblVault buyout duration longer than update timelock
119.21 USDC • Code4rena • reassor
#41
188.08 USDC • Code4rena • reassor
#15
201.29 USDC • 1 total finding • Code4rena • reassor
#33
Protocol fee rate can be arbitrarily modified by the owner and the new rate will apply to all existing orders
May '22
544.82 USDT • Code4rena • reassor
#28
133.19 USDC • Code4rena • reassor
#44
175.07 USDC • 2 total findings • Code4rena • reassor
BathToken LPs Unable To Receive Bonus Token Due To Lack Of Wallet Setter Method
No cap on fees can result in a DOS in BathToken.withdraw()
682.04 USDC • Code4rena • reassor
96.33 USDC • 2 total findings • Code4rena • reassor
#38
Owner can modify the feeRate on existing vaults and steal the strike value on exercise
Vault is Not Compatible with Fee Tokens and Vaults with Such Tokens Could Be Exploited
680.69 DAI • 4 total findings • Code4rena • reassor
#12
SpeedBumpPriceGate: Excess ether did not return to the user
amount requires to be updated to contract balance increase (1)
ERC20 tokens with different decimals than 18 leads to loss of funds
Centralisation Risk: Owner may abuse the tax rate to claim 99.9% of pools
651.51 USDC • 1 total finding • Code4rena • reassor
#19
Protocol doesn't handle fee on transfer tokens
515.73 USDC • 2 total findings • Code4rena • reassor
#20
Use of `.send()` May Revert if The Recipient's Fallback Function Consumes More Than 2300 Gas
Many unbounded and under-constrained variables in the system can lead to unfair price or DoS
Apr '22
377.45 USDC • 1 total finding • Code4rena • reassor
#13
_depositAmount requires to be updated to contract balance increase
232.66 MIM • Code4rena • reassor
#22
351.93 USDC • 2 total findings • Code4rena • reassor
#26
_revokeRole doesn't remove account from roleMember set
Chainlink's latestRoundData might return stale or incorrect results
22.05 USDC • 1 total finding • Code4rena • reassor
#35
2,832.74 USDC • 2 total findings • Code4rena • reassor
#10
StakedCitadel: wrong setupVesting function name
KnightingRound tokenOutPrice changes
177.29 USDC • 1 total finding • Code4rena • reassor
Chainlink pricer is using a deprecated API
78.24 USDC • Code4rena • reassor
#14
102.04 USDC • Code4rena • reassor
#25
Mar '22
2,674.53 USDC • 1 total finding • Code4rena • reassor
#6
Emergency mode enable/disable issue
Feb '22
538.97 USDC • 2 total findings • Code4rena • reassor
Donated Tokens Cannot Be Recovered If A Shelter Is Deactivated
[ConcurRewardPool] Possible reentrancy when claiming rewards