https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

timefliez

Security Researcher

Contact Me

High

12

Total

Medium

16

Total

$8.91K

Total Earnings

#673 All Time

8x

Payouts

regular

3x

Top 10

regular

4x

Top 25

regular

5x

Top 50

All

Cantina

CodeHawks

Aug '25

kuru-contracts

kuru-contracts

1,635.94 USDC • 2 total findings • Cantina • timefliez

#13

high

Finding not yet public.

medium

Finding not yet public.

May '25

ammalgam-contracts

ammalgam-contracts

3,786.91 USDC • 1 total finding • Cantina • timefliez

#4

medium

Finding not yet public.

jigsaw-contracts

jigsaw-contracts

62.31 USDC • 2 total findings • Cantina • timefliez

#61

high

Finding not yet public.

high

Finding not yet public.

alchemix-v3

alchemix-v3

134.64 USDC • 2 total findings • Cantina • timefliez

#51

high

Finding not yet public.

medium

Finding not yet public.

Feb '25

Core Contracts

Core Contracts

89.50 usdc • 19 total findings • CodeHawks • 0xtimefliez

#155

high

RAACNFT mint function receives funds to address(this) but has no way of withdrawing them

high

Reward manipulation vulnerability in StabilityPool

high

Users can borrow more assets than they have deposited as collateral

high

NFTs Get Permanently Locked in Stability Pool After Liquidation

high

Any attempt to liquidate a user will fail, because StabilityPool does not hold crvUSD during operational lifecycle

high

Double Usage Index Scaling in StabilityPool Liquidation Inflates Required CRVUSD Balance

high

Untracked Direct Fee Transfers from RAACToken to FeeCollector Break Fee Distribution System

medium

RToken.transferFrom() Does Not Scale User Balances Due to Stale Liquidity Index

medium

Users Can Lose Funds and Collateral by Repaying Loans After Liquidation Grace Period Expiry

medium

There is no logic checking for RAACNFT price staleness before minting it

medium

Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations

medium

Liquidations are enabled when repayments are disabled, causing borrowers to lose funds without a chance to repay

medium

Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator

medium

Multiple Token Management Lets Withdraw a Token Different than Deposited Token

medium

Flawed Boost Multiplier Calculation Always Yields Maximum Boost

medium

balanceOf(address(this)) in StabilityPool causes reward distribution to be higher than it should be

medium

The earned yield from the Curve vault can never be utilized when withdrawing or borrowing

medium

closeLiquidation within LendingPool does not allow partial repayments, which can cause massive losses to users within edge case

low

Incorrect Timestamp Tracking in RAACHousePrice contract

Jan '25

Part 2

Part 2

1,998.84 usdc • 2 total findings • CodeHawks • 0xtimefliez

#10

high

Incorrect `AutoDeleverageFactor`.

medium

Unable to swap USD token to collateral for vaults in credit

Ignite

Ignite

1,188.86 usdc • CodeHawks • 0xtimefliez

#4

Dec '24

Alchemix Transmuter

Alchemix Transmuter

11.67 op • 1 total finding • CodeHawks • 0xtimefliez

#27

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.