Security Researcher
It's /ʲustɑs/ • security research • privacy • FOSS
High
Total
Medium
Total Earnings
#358 All Time
Payouts
2nd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
Jun '25
1.42 USDC • Code4rena • ustas
#8
Dec '24
6,989.01 USDC • 7 total findings • Cantina • ustas
high
medium
Jul '24
2.09 USDC • 1 total finding • Code4rena • ustas
#54
WhenNotPaused modifier in the CDPVault can be bypassed by users
Nov '23
11.32 USDC • 1 total finding • Code4rena • ustas
#28
Attacker can steal all fees from SFPM in pools with ERC777 tokens.
691.74 USDC • 2 total findings • Code4rena • ustas
Owner cannot withdraw all interest due to wrong calculation of accrued interest in WithdrwaCarry
No slippage protection for Market functions
Oct '23
95.88 USDC • 2 total findings • Code4rena • ustas
#61
Attacker can reenter to mint all the collection supply
Vulnerability in burnToMint function allowing double use of NFT
12,177.85 USDC • Code4rena • ustas
#11
Sep '23
25.79 USDC • 1 total finding • Code4rena • ustas
All tokens can be stolen from `VirtualAccount` due to missing access modifier
1.46 USDC • 1 total finding • Sherlock • ustas
#67
`useRegistryAnchor == true` breakes the logics of `RFPSimpleStrategy._registerRecipient()`
May '23
15.95 USDC • 3 total findings • Sherlock • ustas
#63
ETH/USD price feed is used instead of BTC/USD
Missing redeem functionality
latestTimestamp is not checked in Oracles
Jan '23
308.3 USDC • 3 total findings • Code4rena • ustas
#48
Modifier VaultController._verifyCreatorOrOwner does not work as intented
`Vault.redeem` function does not use `syncFeeCheckpoint` modifier
`Vault::takeFees` can be front run to minimize `accruedPerformanceFee`
854.40 USDC • Sherlock • ustas
#15
917.62 USDC • 1 total finding • Code4rena • ustas
#22
attacker can steal RToken holders funds by performing reentrancy attack during redeem() function token transfers