Security Researcher
High
Total
Medium
Total Earnings
#219 All Time
Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
Jan '25
190.02 USDC • Sherlock • sorrynotsorry
#63
Dec '24
583.61 USDC • Sherlock • sorrynotsorry
#8
Nov '23
1,243.18 USDC • 1 total finding • Cantina • sorryNotsorry
#15
high
Oct '23
123.66 USDC • 1 total finding • Code4rena • sorrynotsorry
#25
medium
``FULL_RESTRICTED`` Stakers can bypass restriction through approvals
23.96 USDC • Code4rena • sorrynotsorry
#12
Aug '23
389.84 USDC • Code4rena • sorrynotsorry
#43
Jul '23
136.05 USDC • Sherlock • sorrynotsorry
#11
Apr '23
22.6 USDC • Code4rena • sorrynotsorry
#66
Mar '23
78.86 USDC • Code4rena • sorrynotsorry
#30
Jan '23
35.48 USDC • Code4rena • sorrynotsorry
#84
44.97 CANTO • Code4rena • sorrynotsorry
#13
4,626 USDC • 1 total finding • Code4rena • sorrynotsorry
#4
sqrtDiscriminant can be calculated wrong
36.5 USDC • Code4rena • sorrynotsorry
#55
Dec '22
0.84 USDC • 1 total finding • Code4rena • sorrynotsorry
#69
`LPDA` price can underflow the price due to bad settings and potentially brick the contract
Nov '22
2,197.91 CANTO • Code4rena • sorrynotsorry
Oct '22
24.6 USDC • 2 total findings • Code4rena • sorrynotsorry
#45
Oracle assumes token and feed decimals will be limited to 18 decimals
Chainlink oracle data feed is not sufficiently validated and can return stale `price`
495.13 USDC • 2 total findings • Sherlock • sorrynotsorry
LienToken's `calculateSlope` might panic
LienToken's `_getInterest` function logic is wrong
0.01 USDC • 1 total finding • Code4rena • sorrynotsorry
#32
Very critical `Owner` privileges can cause complete destruction of the project in a possible privateKey exploit
99.78 USDC • 1 total finding • Sherlock • sorrynotsorry
#9
DOS with zero share minting
Sep '22
52.04 USDC • Code4rena • sorrynotsorry
#50
3,030.46 USDC • 1 total finding • Code4rena • sorrynotsorry
_releaseIntervalSecs is not validated
34.5 USDC • Code4rena • sorrynotsorry
#10
1,212.51 CANTO • Code4rena • sorrynotsorry
#6
445.45 USDC • 1 total finding • Code4rena • sorrynotsorry
#39
Auction parameters can be changed during ongoing auction
Aug '22
533.47 USDC • 1 total finding • Sherlock • sorrynotsorry
#17
Chainlink price decimals are assumed as 18
536.51 USDC • 1 total finding • Code4rena • sorrynotsorry
#33
TRSRY: front-runnable `setApprovalFor`
Jul '22
329.66 USDC • 1 total finding • Code4rena • sorrynotsorry
#37
Vault implementation can be destroyed leading to loss of all assets
Jun '22
28.42 USDC • Code4rena • sorrynotsorry
#56
298.2 USDC • Code4rena • sorrynotsorry
49.05 USDC • Code4rena • sorrynotsorry
151.39 USDC • Code4rena • sorrynotsorry
#47
261.9 USDC • Code4rena • sorrynotsorry
May '22
2,182.56 USDT • 1 total finding • Code4rena • sorrynotsorry
BaseRewardPool's `rewardPerTokenStored` can be inflated and rewards can be stolen
101.32 USDC • Code4rena • sorrynotsorry
#48
144.3 USDC • 2 total findings • Code4rena • sorrynotsorry
#44
First depositor can break minting of shares
Use `call()` instead of `transfer()` when transferring ETH in RubiconRouter
1,923.74 USDC • Code4rena • sorrynotsorry
1,786.24 USDC • 3 total findings • Code4rena • sorrynotsorry
hard-coded slippage may freeze user funds during market turbulence
The check for value transfer success is made after the return statement in _withdrawFromYieldPool of LidoVault
Title: Yield can be unfairly divided because of MEV/Just-in-time stablecoin deposits
151.97 USDC • Code4rena • sorrynotsorry
54.97 USDC • Code4rena • sorrynotsorry
5,264.32 USDT • Code4rena • sorrynotsorry
#7
176.09 DAI • Code4rena • sorrynotsorry
#28
13,156.6 USDC • 1 total finding • Code4rena • sorrynotsorry
Calls inside loops that may address DoS.
1,216.12 USDC • 2 total findings • Code4rena • sorrynotsorry
Use of `.send()` May Revert if The Recipient's Fallback Function Consumes More Than 2300 Gas
IERC20.transfer does not support all ERC20 token
4,378.51 USDC • 2 total findings • Code4rena • sorrynotsorry
Chainlink pricer is using a deprecated API
`call()` should be used instead of `transfer()` on an `address payable`
Apr '22
164 USDC • Code4rena • sorrynotsorry
#18
44.82 MIM • Code4rena • sorrynotsorry
#52
411.47 USDC • 1 total finding • Code4rena • sorrynotsorry
#23
Chainlink's latestRoundData might return stale or incorrect results
356.74 USDC • Code4rena • sorrynotsorry
428.53 USDC • Code4rena • sorrynotsorry
#27
80.91 USDC • Code4rena • sorrynotsorry
#49
255.68 USDC • Code4rena • sorrynotsorry
96.42 USDC • Code4rena • sorrynotsorry
Mar '22
121.24 USDC • Code4rena • sorrynotsorry
632.5 USDC • 2 total findings • Code4rena • sorrynotsorry
WithdrawFacet's withdraw calls native payable.transfer, which can be unusable for DiamondStorage owner contract
Reputation Risks with `contractOwner`
60.11 USDC • Code4rena • sorrynotsorry
Feb '22
43.82 USDC • Code4rena • sorrynotsorry
50.77 USDC • Code4rena • sorrynotsorry
240.99 USDC • Code4rena • sorrynotsorry
Jan '22
3.38 USDC • Code4rena • sorrynotsorry