https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/424f058e-d4bd-4bcd-9154-1f14ec272d42.jpg

super_jack

Senior Blockchain Auditor

Senior Blockchain Auditor

Contact Me

High

9

Total

Medium

9

Total

$2.25K

Total Earnings

#983 All Time

6x

Payouts

bronze

1x

3rd Places

regular

1x

Top 10

regular

3x

Top 25

All

Sherlock

Feb '25

Yieldoor

Yieldoor

11.40 USDC • 1 total finding • Sherlock • super_jack

#27

medium

The strategy will collect less yield than expected or rebalancing could always fail.

Jan '25

Peapods

Peapods

1,092.23 USDC • 3 total findings • Sherlock • super_jack

#13

high

The yield converting can always be failed in `AutoCompoundingPodLp`.

medium

Wrong calculation of `_vaultAssetRatioChange` will cause loss of assets to users.

medium

Recursive decreasing of `_amountOutMin` will cause loss of funds.

Plaza Finance

Plaza Finance

6.55 USDC • 2 total findings • Sherlock • super_jack

#79

medium

Rounding error of `redeemAmount` is big.

medium

User will lose `balancerPoolToken` and it is freezed to `BalancerRouter`.

Dec '24

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

112.88 OP • 10 total findings • Sherlock • super_jack

#20

high

A malicious user can use other user's signature when withdraw from `CDS`.

high

Attacker can steal all usdt from treasury through `CDS.sol#redeemUSDT()`.

high

An attacker can freeze CDS.

high

An attacker can increase `borrowing.lastCumulativeRate` much bigger without limit causing freeze of borrowing.

high

An attacker can steal funds from treasury.

high

The owner cannot withdraw the interest from liquidation.

high

Admin will lose `eth` or can be not able to liquidate unhealthy position.

medium

An attacker can manipulate `omniChainData.cdsPoolValue` by breaking protocol.

medium

The `borrowing.lastCumulateRate` is updated wrongly when withdrawal from borrowing.

medium

Wrong applying of `lastCumulativeRate` can lead to increasing of borrower's debt or decreasing borrower's repay amount, unexpectedly.

Oct '24

Usual V1

Usual V1

1,013.20 USDC • 1 total finding • Sherlock • super_jack

bronze

high

The user will withdraw funds with less fee from protocol or first depositor will make share price much bigger.

Sep '24

Flayer

Flayer

19.21 USDC • 1 total finding • Sherlock • super_jack

#66

medium

A user loses funds when he modifies only price of listings.