https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

stackachu

Security Researcher

Contact Me

High

11

Total

Medium

3

Total

$805.00

Total Earnings

#1371 All Time

8x

Payouts

regular

2x

Top 50

All

Code4rena

Mar '24

Revert Lend

Revert Lend

17.32 USDC • 1 total finding • Code4rena • stackachu

#67

high

Owner of a position can prevent liquidation due to the 'onERC721Received' callback

Feb '24

AI Arena

AI Arena

1.37 USDC • 3 total findings • Code4rena • stackachu

#164

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

Jan '24

Salty.IO

Salty.IO

493.89 USDC • 5 total findings • Code4rena • stackachu

#26

high

User can evade `liquidation` by depositing the minimum of tokens and gain time to not be liquidated

high

First depositor can break staking-rewards accounting

high

First Liquidity provider can claim all initial pool rewards

medium

THE USER WHO WITHDRAWS LIQUIDITY FROM A PARTICULAR POOL IS ABLE TO CLAIM MORE REWARDS THAN HE DULY DESERVES BY CAREFULLY SELECTING A `decreaseShareAmount` VALUE SUCH THAT THE `virtualRewardsToRemove` IS ROUNDED DOWN TO ZERO

medium

Impossible to change managed wallets with `proposeWallets` after first rejection

reNFT

reNFT

32.53 USDC • Code4rena • stackachu

#49

Dec '23

Ethereum Credit Guild

Ethereum Credit Guild

240.77 USDC • 2 total findings • Code4rena • stackachu

#52

high

Users staking via the `SurplusGuildMinter` can be immediately slashed when staking into a gauge that had previously incurred a loss

high

Anyone can steal all distributed rewards

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

2.76 USDC • Code4rena • stackachu

#54

Oct '23

NextGen

NextGen

0.15 USDC • 1 total finding • Code4rena • stackachu

#112

high

Attacker can reenter to mint all the collection supply

The Wildcat Protocol

The Wildcat Protocol

16.72 USDC • 2 total findings • Code4rena • stackachu

#61

high

Borrower has no way to update `maxTotalSupply` of `market` or close market.

medium

Function WildcatMarketController.setAnnualInterestBips allows for values outside the factory range