Security Researcher
High
Total
Medium
Total Earnings
#756 All Time
Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Apr '24
141.61 USDC • 1 total finding • Sherlock • thank_you
#41
medium
Borrower can escape paying last payment cycle interest
Mar '24
1.18 USDC • 1 total finding • Sherlock • thank_you
high
Bidders can cancel their own bid when they are the highest bidder
25.12 USDC • 2 total findings • Sherlock • thank_you
#10
Users can claim vested tokens more than once through re-entrancy
Unable to update Vesting user deposits when token is represented as Ether
2,564.06 USDC • 3 total findings • Code4rena • thank_you
#5
`V3Vault.sol` permit signature does not check receiving token address is USDC
Liquidation reward sent to msg.sender instead of recipient
setReserveFactor fails to update global interest before updating reserve factor
Feb '24
80.56 USDC • 1 total finding • Code4rena • thank_you
#25
`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.
0.14 USDC • 3 total findings • Code4rena • thank_you
#180
A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters
Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`
Can mint NFT with the desired attributes by reverting transaction
Jan '24
228.10 USDC • 2 total findings • Sherlock • thank_you
#9
Unstakings are never deleted leading to addValidatorAddress DOSing permanently
OperationalStaking.stake() has no slippage checks
17.38 USDC • 1 total finding • Sherlock • thank_you
#7
Anyone can participate in a future round for free
1.08 USDC • 1 total finding • Code4rena • thank_you
#129
Attack to make ````CurveSubject```` to be a ````HoneyPot````
Dec '23
358.73 USDC • 1 total finding • Code4rena • thank_you
#15
Missing slippage protection in `liquidity_lockbox::withdraw`
172.15 USDC • 1 total finding • Sherlock • thank_you
First LP can DOS future LP stakers by withdrawing assets back to GSP contract
30.41 USDC • 1 total finding • Code4rena • thank_you
#81
LendingTerm::debtCeiling() can return wrong debt as the min() is evaluated incorrectly
Aug '22
84.04 USDC • 1 total finding • Code4rena • thank_you
#28
Possible to bypass saleConfig.limitPerAccount
Jan '22
766.73 USDC • 1 total finding • Code4rena • thank_you
#11
XSS via SVG Construction contract
Nov '21
20.04 USDC • 1 total finding • Code4rena • thank_you
#30
Frontrunning in UniswapHandler calls to UniswapV2Router