https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/fc59edcd-4709-4df5-b87f-aa4f5f6b68fb.png

rokinot

Security Researcher

third world finance. computer engineer student. @code4rena

Contact Me

High

7

Total

Medium

2

Solo

11

Total

$6.17K

Total Earnings

#706 All Time

30x

Payouts

silver

1x

2nd Places

regular

4x

Top 10

regular

11x

Top 25

All

Sherlock

Code4rena

Hats Finance

Feb '25

Rova

Rova

1,178.25 USDC • 1 total finding • Sherlock • rokinot

silver

medium

User can be DoSed after upgrading due to incorrect internal accounting

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

242.11 USDC • 1 total finding • Code4rena • rokinot

#13

medium

Withdrawal from NFTs can be temporarily blocked

Jan '24

Ion Protocol

Ion Protocol

797.5 USDC • 2 total findings • Hats • rokinot

#5

medium

`reserveFactor` validation check cannot revert in case of invalid value assignment.

medium

`payable` modifier on function without use of native currency can lead to locked ETH

reNFT

reNFT

27.78 USDC • Code4rena • rokinot

#52

Oct '23

Ethena Labs

Ethena Labs

4.52 USDC • Code4rena • rokinot

#40

Sep '23

Venus Prime

Venus Prime

327.81 USDC • 2 total findings • Code4rena • rokinot

#14

high

A malicious user can avoid unfavorable score updates after alpha/multiplier changes, resulting in accrual of outsized rewards for the attacker at the expense of other users

high

Prime.sol - User can claim Prime token without having any staked XVS, because his `stakedAt` isn't reset whenever he is issued an irrevocable token.

Centrifuge

Centrifuge

47.48 USDC • Code4rena • rokinot

#32

Aug '23

Dopex

Dopex

271.48 USDC • 2 total findings • Code4rena • rokinot

#51

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP

high

`UniV3LiquidityAMO::recoverERC721` will cause `ERC721` tokens to be permanently locked in `rdpxV2Core`

Jul '23

Tapioca DAO

Tapioca DAO

224.93 USDC • 1 total finding • Code4rena • rokinot

#64

medium

The twTAP multiplier can be compromised with manipulated deposits of low value cost and high duration

Mar '23

Lodestar Finance

Lodestar Finance

527.7 USDC • Hats • rokinot

#7

Oct '22

Inverse Finance contest

Inverse Finance contest

0.38 USDC • 1 total finding • Code4rena • rokinot

#50

medium

Chainlink oracle data feed is not sufficiently validated and can return stale `price`

3xcalibur contest

3xcalibur contest

0 USDC • Code4rena • rokinot

#39

Blur Exchange contest

Blur Exchange contest

114.82 USDC • 1 total finding • Code4rena • rokinot

#20

high

StandardPolicyERC1155.sol returns amount == 1 instead of amount == order.amount

Sep '22

Frax Ether Liquid Staking contest

Frax Ether Liquid Staking contest

53.31 USDC • 1 total finding • Code4rena • rokinot

#47

medium

frxETHMinter: Non-conforming ERC20 tokens not recoverable

VTVL contest

VTVL contest

416.87 USDC • 1 total finding • Code4rena • rokinot

#15

high

Permanent freeze of vested tokens due to overflow in _baseVestedAmount

Y2k Finance contest

Y2k Finance contest

169.47 USDC • 1 total finding • Code4rena • rokinot

#33

medium

`timewindow` can be changed unexpectedly that blocks users from calling `deposit` function

FEI and TRIBE Redemption contest

FEI and TRIBE Redemption contest

33.58 USDC • Code4rena • rokinot

#14

Canto Dex Oracle contest

Canto Dex Oracle contest

146.62 CANTO • 1 total finding • Code4rena • rokinot

#10

medium

unbounded loop length dos

Aug '22

Olympus DAO contest

Olympus DAO contest

86.89 USDC • Code4rena • rokinot

#78

Nouns DAO contest

Nouns DAO contest

52.1 USDC • Code4rena • rokinot

#38

FIAT DAO veFDT contest

FIAT DAO veFDT contest

434.83 USDC • 1 total finding • Code4rena • rokinot

#14

medium

Attacker contract can avoid being blocked by BlockList.sol

Foundation Drop contest

Foundation Drop contest

41.21 USDC • Code4rena • rokinot

#58

Rigor Protocol contest

Rigor Protocol contest

179.3 USDC • 1 total finding • Code4rena • rokinot

#34

high

Project funds can be drained by reusing signatures, in some cases

Jul '22

Golom contest

Golom contest

188.25 USDC • Code4rena • rokinot

#56

Yield Witch v2 contest

Yield Witch v2 contest

56.13 USDC • Code4rena • rokinot

#26

Swivel v3 contest

Swivel v3 contest

177.79 USDC • 1 total finding • Code4rena • rokinot

#17

medium

Interface definition error

ENS contest

ENS contest

118.9 USDC • Code4rena • rokinot

#54

Fractional v2 contest

Fractional v2 contest

99.41 USDC • Code4rena • rokinot

#78

Jun '22

Putty contest

Putty contest

68.48 USDC • Code4rena • rokinot

#66

Apr '22

JPEG'd contest

JPEG'd contest

82.45 USDC • Code4rena • rokinot

#48