https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/5364aac0-32e1-4752-b902-4ba119f9f4aa.jpg

trachev

Security Researcher

Web3 Security Researcher

Contact Me

High

14

Total

Medium

1

Solo

13

Total

$5.71K

Total Earnings

#708 All Time

6x

Payouts

regular

3x

Top 10

regular

5x

Top 25

regular

5x

Top 50

All

Sherlock

Aug '24

ZeroLend One

ZeroLend One

999.60 USDC • 10 total findings • Sherlock • trachev

#13

high

Debt rates will be wrongly set when debt is repaid

high

Borrow rates are easily manipulatable due to `nextDebtShares` being set to a wrong value

high

Treasury fee shares are removed from `totalSupply.supplyShares`, causing withdrawals to fail

high

Borrowers cannot be fully liquidated, due to `executeLiquidationCall` not converting shares into assets

high

The liquidation protocol fee is not reduced from the total supply shares, allowing liquidated borrowers to steal from other users

high

`CuratedVault` depositors are able to get more shares than intended by the protocol, stealing from other depositors

high

`PositionBalanceConfiguration`'s `getSupplyBalance` and `getDebtBalance` are implemented incorrectly causing numerous criticial issues

medium

Treasury fees are not considered when calculating interest rates after withdrawals

medium

`reallocate` reverts if all pool's assets are reallocated

medium

`withdrawable` may return a too high amount, causing a revert and preventing users from withdrawing their assets from curated vaults

Jul '24

Union Finance Update #2

Union Finance Update #2

1,909.23 USDC • 5 total findings • Sherlock • trachev

#4

high

`repayBorrowWithERC20Permit` supplies incorrect interest value to `_repayBorrowFresh`

high

`debtWriteOff` incorrectly reduces `_totalStaked`, causing rewards to be inaccurate

high

All tokens can be stolen from `VouchFaucet.sol`

medium

Any user can claim an unlimited amount of vouch in `VouchFaucet.sol`

medium

`onERC1155BatchReceived` can be called by any address

May '24

PoolTogether: The Prize Layer for DeFi

PoolTogether: The Prize Layer for DeFi

1,897.91 USDC • 4 total findings • Sherlock • trachev

#8

high

`finishDraw` will fail in many occurences due to unpredictable calculations

medium

The `canStartDraw` function may return wrong data, causing loss of funds

medium

Users may be unable to withdraw from their `Requestor` contract

medium

The protocol will not function on many of the required chains

Apr '24

TITLES Publishing Protocol

TITLES Publishing Protocol

80.35 USDC • 5 total findings • Sherlock • trachev

#25

high

Users can mint tokens for free in the second `mintBatch` function

high

`collectionReferrerShare` is sent to the wrong address

medium

`mintBatch` will revert in almost all cases

medium

No funds can be refunded

medium

TitlesGraph.sol is not initialized

Sep '23

Allo V2

Allo V2

37.17 USDC • 2 total findings • Sherlock • trachev

#52

medium

User can escape from paying fees when funding a pool

medium

Recipients are given more votes than intended to

Jul '23

GFX Labs

GFX Labs

785.72 USDC • 1 total finding • Sherlock • trachev

#6

high

High - Owner can accidentally withdraw users' funds