Security Researcher
Protect Your Web3 Protocol With Our Expert Security Solutions
High
Total
Medium
Total Earnings
#548 All Time
Payouts
2nd Places
Top 10
Top 25
All
Code4rena
May '25
54 USDC • Code4rena • Sparrow
#26
Mar '25
315.79 USDC • Code4rena • Sparrow
#20
Feb '25
4,178.13 USDC • 1 total finding • Code4rena • Sparrow
#8
medium
Edge case breaks APR cap calculation and leads to excessive fee extraction from the pool
165.79 USDC • Code4rena • Sparrow
#4
947.37 USDC • Code4rena • Sparrow
663.16 USDC • Code4rena • Sparrow
#7
Jan '25
0 USDC • 1 total finding • Code4rena • Sparrow
#12
Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions
3.58 USDC • 1 total finding • Code4rena • Sparrow
#16
Ineffective proposal threshold validation allows setting arbitrary high values
221.05 USDC • Code4rena • Sparrow
Dec '24
862.48 USDC • 1 total finding • Code4rena • Sparrow
Missing slippage protection in `AerodromeDexter.sol` `swapExactTokensForTokens()`
Nov '24
12.22 USDC • 1 total finding • Code4rena • Sparrow
#22
`withdraw_liquidity` lacks slippage protection
635.79 USDC • Code4rena • Sparrow
#25
1,473.68 USDC • Code4rena • Sparrow
#5
Oct '24
0 USDC • Code4rena • Sparrow
Aug '24
0.02 USDT • 1 total finding • Code4rena • Sparrow
#67
high
SettlementSignatureVerifier is missing check for duplicate validator signatures
1.26 USDC • 1 total finding • Code4rena • Sparrow
#32
_onTransferReceived() does not work as intended
21.42 USDC • 1 total finding • Code4rena • Sparrow
#38
Signature replay in `createArt` allows to impersonate artist and steal royalties
Jul '24
220.95 USDC • 2 total findings • Code4rena • Sparrow
#33
`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`
`SwapAction.sol#balancerSwap` does not support native ETH as input token.
0 OP • Code4rena • Sparrow
#14
May '24
232.44 USDC • 1 total finding • Code4rena • Sparrow
Incorrect Handling of Last Nominee Removal in `removeNominee` Function
55.39 USDC • 3 total findings • Code4rena • Sparrow
#24
incorrect price for negative ticks due to lack of rounding down
Liquidity manipulation is possible when trading
Chainlink's `latestRoundData` might return stale or incorrect results
Apr '24
#58
19.18 USDC + NOYA stars • 1 total finding • Code4rena • Sparrow
#82
Chainlink connector doesn’t check for the Min / Max prices returned