https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

sseefried

Security Researcher

Contact Me

High

8

Total

Medium

15

Total

$25.77K

Total Earnings

#324 All Time

23x

Payouts

bronze

2x

3rd Places

regular

3x

Top 10

regular

11x

Top 25

All

Code4rena

Aug '22

Nouns DAO contest

Nouns DAO contest

35.44 USDC • Code4rena • sseefried

#41

FIAT DAO veFDT contest

FIAT DAO veFDT contest

29.89 USDC • Code4rena • sseefried

#66

Fraxlend (Frax Finance) contest

Fraxlend (Frax Finance) contest

1,141.05 USDC • 1 total finding • Code4rena • sseefried

#12

medium

Interest can be significantly lower if `addInterest` isn't called frequently enough

Rigor Protocol contest

Rigor Protocol contest

941.62 USDC • 5 total findings • Code4rena • sseefried

#14

high

Builder can call `Community.escrow` again to reduce debt further using same signatures

high

Builder can halve the interest paid to a community owner due to arithmetic rounding

high

Project funds can be drained by reusing signatures, in some cases

medium

Attacker can drain all the projects within minutes, if admin account has been exposed

medium

Missing upper limit definition in replaceLenderFee() of HomeFi.sol

Jul '22

Axelar Network v2 contest

Axelar Network v2 contest

56.16 USDC • Code4rena • sseefried

#41

Golom contest

Golom contest

382.1 USDC • Code4rena • sseefried

#33

Fractional v2 contest

Fractional v2 contest

2,097.92 USDC • 4 total findings • Code4rena • sseefried

#12

high

Proposer can `start` a perpetual buyout which can only `end` if the auction succeeds and is not rejected

medium

An attacker can DoS vault's buyout with as little as 1 wei per 4 days

medium

Delegate call in `Vault#_execute` can alter Vault's ownership

medium

Use of `payable.transfer()` may lock user funds

Jun '22

Putty contest

Putty contest

842.77 USDC • 3 total findings • Code4rena • sseefried

#19

medium

`fillOrder()` and `exercise()` may lock Ether sent to the contract, forever

medium

`fee` can change without the consent of users

medium

Overlap Between `ERC721.transferFrom()` and `ERC20.transferFrom()` Allows `order.erc20Assets` or `order.baseAsset` To Be ERC721 Rather Than ERC20

Nibbl contest

Nibbl contest

28.33 USDC • Code4rena • sseefried

#60

Yieldy contest

Yieldy contest

53.14 USDC • Code4rena • sseefried

#64

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

49.01 USDC • Code4rena • sseefried

#68

Notional x Index Coop

Notional x Index Coop

89.19 USDC • Code4rena • sseefried

#38

May '22

veToken Finance contest

veToken Finance contest

1,055.99 USDT • 1 total finding • Code4rena • sseefried

#18

medium

Not updating `totalWeight` when operator is removed in `VeTokenMinter`

Rubicon contest

Rubicon contest

1,094.83 USDC • 3 total findings • Code4rena • sseefried

#16

high

BathToken LPs Unable To Receive Bonus Token Due To Lack Of Wallet Setter Method

medium

`BathBuddy` contract's `vestedAmount` function includes fees leading to users being disproportionately rewarded after whale withdraws

medium

No cap on fees can result in a DOS in BathToken.withdraw()

Sturdy contest

Sturdy contest

14.84 USDC • 1 total finding • Code4rena • sseefried

#55

high

The check for value transfer success is made after the return statement in _withdrawFromYieldPool of LidoVault

Aura Finance contest

Aura Finance contest

150.03 USDC • Code4rena • sseefried

#45

Cally contest

Cally contest

3,583.46 USDC • 3 total findings • Code4rena • sseefried

bronze

high

Inefficiency in the Dutch Auction due to lower duration

medium

Expiration calculation overflows if call option duration ≥ 195 days

medium

Owner can modify the feeRate on existing vaults and steal the strike value on exercise

Forgotten Runes Warrior Guild contest

Forgotten Runes Warrior Guild contest

35.02 USDC • Code4rena • sseefried

#54

Apr '22

Backd contest

Backd contest

4,493.16 USDC • 1 total finding • Code4rena • sseefried

#6

medium

Malicious Stakers can grief Keepers

Phuture Finance contest

Phuture Finance contest

62.99 USDC • Code4rena • sseefried

#28

Axelar Network contest

Axelar Network contest

9,107.14 USDC • 1 total finding • Code4rena • sseefried

bronze

high

Cross-chain smart contract calls can revert but source chain tokens remain burnt and are not refunded

Mar '22

Paladin contest

Paladin contest

302.88 USDC • Code4rena • sseefried

#19

Sublime contest

Sublime contest

122.89 USDC • Code4rena • sseefried

#14