Security Researcher
High
Total
Medium
Total Earnings
#483 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Dec '22
843.01 USDC • 1 total finding • Code4rena • shung
#10
high
Liquidity providers may lose funds when adding liquidity
Oct '22
2,139.51 USDC • 1 total finding • Code4rena • shung
#12
medium
Attacker can keep fees max at no cost
Sep '22
1,009.04 USDC • 1 total finding • Sherlock • shung
Internal `OptionMath._getPositivePlaceValues()` function do not handle values below `185`
594.22 USDC • 1 total finding • Code4rena • shung
#16
The reveal process could brick if `randProvider` stops working
Jun '22
1,397.16 USDC • 2 total findings • Code4rena • shung
#13
Order cancellation is prone to frontrunning and is dependent on a centralized database
Unbounded loops may cause `exercise()`s and `withdraw()`s to fail
440.97 USDC • 3 total findings • Code4rena • shung
#23
`Staking.sol#stake()` DoS by staking 1 wei for the recipient when `warmUpPeriod > 0`
No way to set CURVE_POOL approval after setting new curve pool address
`_storeRebase()` is called with the wrong parameters
May '22
5,202.73 USDC • Code4rena • shung
319.71 USDC • 1 total finding • Code4rena • shung
#19
Owner can modify the feeRate on existing vaults and steal the strike value on exercise
348.3 USDC • 1 total finding • Code4rena • shung
#22
Many unbounded and under-constrained variables in the system can lead to unfair price or DoS