https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

tripathi

Security Researcher

Contact Me

High

1

Solo

7

Total

Medium

4

Solo

18

Total

$61.89K

Total Earnings

#165 All Time

14x

Payouts

gold

2x

1st Places

silver

1x

2nd Places

regular

7x

Top 10

All

Code4rena

Cantina

Hats Finance

Jan '25

hmx-orderbook

hmx-orderbook

13,365.35 USDC • 1 total finding • Cantina • Tripathi

gold

high

Finding not yet public.

Nov '24

hyperlend

hyperlend

39,953.3 USDC • 3 total findings • Cantina • Tripathi

gold

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

Fenix

Fenix

300 USDC • 1 total finding • Hats • Tripathi

#6

medium

In reward calculation, dust amount is left and stuck in the contract for every epoch

Jun '24

Velvet Capital

Velvet Capital

4,000 USDT • 1 total finding • Hats • Tripathi

#4

medium

Accrued Fees Not Minted before Fee Parameters Are Updated

Safe

Safe

249.6 USDC • 1 total finding • Hats • Tripathi

#4

low

Does not emit event after writing into storage

May '24

Predy

Predy

0.17 USDC • 1 total finding • Code4rena • Tripathi

#42

medium

Chainlink's `latestRoundData` might return stale or incorrect results

Mar '24

Smart-contracts

Smart-contracts

171.17 USDC • 3 total findings • Cantina • Tripathi

#26

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

PoolTogether

PoolTogether

165.52 USDC • 4 total findings • Code4rena • Tripathi

#19

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

medium

In important libraries of PoolTogether, the pow() function of PRBMath is used, which exhibits inconsistent return values

medium

`drawManager` CAN BE SET TO A MALICIOUS ADDRESS

medium

Lack of Slippage Protection in `withdraw`/`redeem` Functions of the Vault

Feb '24

Origami

Origami

559.5 DAI • 1 total finding • Hats • Tripathi

#8

medium

Rounding in LovTokenManager doesn't sync with design

Wise Lending

Wise Lending

2,500 USDC • 2 total findings • Hats • Tripathi

silver

high

`WiseSecurity.checksWithdraw` blocks the withdrawal of pooltokens

medium

`WiseOracleHub.getTokensPriceFromUSD()`skips TWAP computation which permits the use of price even if the difference >`ALLOWED_DIFFERENCE`

Jan '24

Salty.IO

Salty.IO

163.11 USDC • 3 total findings • Code4rena • Tripathi

#56

medium

formPOL lacks slippage and deadline protection

medium

No proposal time limit traps sponsors of unpopular proposals

medium

Chainlink price feed uses BTC, not WBTC. In case of depegging, oracles will become easier to manipulate.

Aug '23

veRWA

veRWA

53.89 USDC • 1 total finding • Code4rena • Tripathi

#37

high

If governance removes a gauge, user's voting power for that gauge will be lost.

Jul '23

PoolTogether

PoolTogether

360.73 USDC • 4 total findings • Code4rena • Tripathi

#36

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

medium

In important libraries of PoolTogether, the pow() function of PRBMath is used, which exhibits inconsistent return values

medium

`drawManager` CAN BE SET TO A MALICIOUS ADDRESS

medium

Lack of Slippage Protection in `withdraw`/`redeem` Functions of the Vault

May '23

Juicebox Buyback Delegate

Juicebox Buyback Delegate

44.17 USDC • Code4rena • Tripathi

#16