https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

stopthecap

Security Researcher

Contact Me

High

2

Solo

7

Total

Medium

1

Solo

8

Total

$70.68K

Total Earnings

#140 All Time

7x

Payouts

bronze

1x

3rd Places

regular

7x

Top 10

regular

7x

Top 25

All

Sherlock

Jul '23

Tokensoft

Tokensoft

6,341.45 USDC • 2 total findings • Sherlock • stopthecap

#7

high

Anyone can mint tokens by re-using their proof

medium

_getOraclePrice() doesn't check If Arbitrum sequencer is down in Chainlink feeds

Jun '23

GLIF

GLIF

16,089.88 USDC • Sherlock • stopthecap

#7

Findings not publicly available for private contests.

Unstoppable

Unstoppable

10,976.02 USDC • 4 total findings • Sherlock • stopthecap

#9

high

DOS protocol by continuely triggering the `is_accepting_new_orders` false state by passing a low `min_amount_out`

medium

Incorrect calculation of the slippage when reducing positions .

medium

Hardcoded threshold does not hold true for several trending and widely used tokens

medium

Debt is not updated when removing margin from a position

RealWagmi

RealWagmi

9,273.13 USDC • 2 total findings • Sherlock • stopthecap

#10

high

Wrong calculation of `tickCumulatives` due to hardcoded pool fees

high

Usage of `slot0` is extremely easy to manipulate

Unitas Protocol

Unitas Protocol

11,656.57 USDC • 3 total findings • Sherlock • stopthecap

#5

medium

If any stable depegs, oracle will fail, disabling swaps

medium

No clear threshold on when the oracle is updated will cause stale prices to be accepted

medium

No slippage or deadline control for swapping while stability burning

May '23

Eco Protocol

Eco Protocol

4,000 USDC • Sherlock • stopthecap

#7

Feb '23

GMX

GMX

12,341.17 USDC • 4 total findings • Sherlock • stopthecap

bronze

high

Creating an order of type MarketIncrease opens an attack vector where attacker can execute txs with stale prices by inputting a very extense swapPath

high

Unpaid funding fees from wrong calculation are going to be substracted from the pool

high

Wrong if statement logic breaks the claimable process

medium

Dividing before multiplication will lead to less fees being paid