https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/5ae5875d-d439-41bd-8709-0927040f1532.jpg

ustas

Security Researcher

Main profile on Lens 🌿 ustas.lens ~~~ Blockchain developer and Security researcher 🦇🔊

Contact Me

High

6

Total

Medium

9

Total

$15.10K

Total Earnings

#417 All Time

11x

Payouts

regular

1x

Top 10

regular

4x

Top 25

regular

6x

Top 50

All

Sherlock

Code4rena

Jul '24

LoopFi

LoopFi

2.09 USDC • 1 total finding • Code4rena • ustas

#54

medium

WhenNotPaused modifier in the CDPVault can be bypassed by users

Nov '23

Panoptic

Panoptic

11.32 USDC • 1 total finding • Code4rena • ustas

#28

high

Attacker can steal all fees from SFPM in pools with ERC777 tokens.

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

691.74 USDC • 2 total findings • Code4rena • ustas

#8

high

Owner cannot withdraw all interest due to wrong calculation of accrued interest in WithdrwaCarry

medium

No slippage protection for Market functions

Oct '23

NextGen

NextGen

95.88 USDC • 2 total findings • Code4rena • ustas

#61

high

Attacker can reenter to mint all the collection supply

medium

Vulnerability in burnToMint function allowing double use of NFT

zkSync Era

zkSync Era

12,177.85 USDC • Code4rena • ustas

#11

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

25.79 USDC • 1 total finding • Code4rena • ustas

#54

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

Allo V2

Allo V2

1.46 USDC • 1 total finding • Sherlock • ustas

#67

medium

`useRegistryAnchor == true` breakes the logics of `RFPSimpleStrategy._registerRecipient()`

May '23

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

15.95 USDC • 3 total findings • Sherlock • ustas

#63

high

ETH/USD price feed is used instead of BTC/USD

medium

Missing redeem functionality

medium

latestTimestamp is not checked in Oracles

Jan '23

Popcorn contest

Popcorn contest

308.3 USDC • 3 total findings • Code4rena • ustas

#48

high

Modifier VaultController._verifyCreatorOrOwner does not work as intented

medium

`Vault.redeem` function does not use `syncFeeCheckpoint` modifier

medium

`Vault::takeFees` can be front run to minimize `accruedPerformanceFee`

Optimism

Optimism

854.40 USDC • Sherlock • ustas

#15

Reserve contest

Reserve contest

917.62 USDC • 1 total finding • Code4rena • ustas

#22

medium

attacker can steal RToken holders funds by performing reentrancy attack during redeem() function token transfers