https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

wagmi

Security Researcher

Contact Me

High

9

Total

Medium

23

Total

$10.83K

Total Earnings

#552 All Time

23x

Payouts

regular

3x

Top 10

regular

10x

Top 25

regular

20x

Top 50

All

Sherlock

Code4rena

Jan '23

Cooler

Cooler

458.33 USDC • 4 total findings • Sherlock • wagmi

#4

high

Use safeTransfer/safeTransferFrom consistently instead of transfer/transferFrom

high

Debt token is transferred to zero address instead of lender when borrower repay full amount

high

Lender can reject receiving repayment through token hook, making the loan defaulted

medium

Loan can have a very long duration because rollable is True by default

UXD Protocol

UXD Protocol

191.07 USDC • 1 total finding • Sherlock • wagmi

#22

high

Function `rebalance()` is vulnerable to sandwich attack

Dec '22

GoGoPool contest

GoGoPool contest

1,504.11 USDC • 8 total findings • Code4rena • wagmi

#20

high

Hijacking of node operators minipool causes loss of staked funds

high

AVAX Assigned High Water is updated incorrectly

medium

MinipoolManager: recordStakingError function does not decrease minipoolCount leading to too high GGP rewards for staker

medium

slashing fails when node operator doesn't have enough staked `GGP`

medium

Cancellation of minipool may skip MinipoolCancelMoratoriumSeconds checking if it was cancelled before

medium

State Transition: Minipools can be created using other operator's AVAX deposit via recreateMinipool

medium

Inflation rate can be reduce by half at most if it get called every 1.99 interval.

medium

NodeOp funds may be trapped by a invalid state transition

Forgeries contest

Forgeries contest

110.27 USDC • 1 total finding • Code4rena • wagmi

#17

medium

Protocol safeguards for time durations are skewed by a factor of 7. Protocol may potentially lock NFT for period of 7 years.

Nov '22

Isomorph

Isomorph

119.90 USDC • 2 total findings • Sherlock • wagmi

#22

medium

Wrong time delay in `isoUSDToken`

medium

Attacker can reduce Vault interest by half because of wrong current block time update in `_updateVirtualPrice()`

Redacted Cartel contest

Redacted Cartel contest

15.93 USDC • 1 total finding • Code4rena • wagmi

#51

medium

Assets may be lost when calling unprotected `AutoPxGlp::compound` function

SIZE contest

SIZE contest

14.14 USDC • 2 total findings • Code4rena • wagmi

#40

medium

Attacker may DOS auctions using invalid bid parameters

medium

Incompatibility with fee-on-transfer/inflationary/deflationary/rebasing tokens, on both base tokens and quote tokens, with varying impacts

Oct '22

Paladin - Warden Pledges contest

Paladin - Warden Pledges contest

9.91 USDC • 1 total finding • Code4rena • wagmi

#35

medium

Owner can transfer all ERC20 reward token out using function recoverERC20

Inverse Finance contest

Inverse Finance contest

36.73 USDC • Code4rena • wagmi

#43

3xcalibur contest

3xcalibur contest

52.23 USDC • Code4rena • wagmi

#29

Trader Joe v2 contest

Trader Joe v2 contest

0.01 USDC • 1 total finding • Code4rena • wagmi

#33

medium

Very critical `Owner` privileges can cause complete destruction of the project in a possible privateKey exploit

Sep '22

Frax Ether Liquid Staking contest

Frax Ether Liquid Staking contest

405.87 USDC • 1 total finding • Code4rena • wagmi

#14

medium

sfrxETH: The volatile result of previewMint() may prevent mintWithSignature from working

VTVL contest

VTVL contest

1,355.96 USDC • 2 total findings • Code4rena • wagmi

#6

medium

possible DoS on vestingRecipients due to lack of disposal mechanism

medium

Supply cap of VariableSupplyERC20Token is not properly enforced

Art Gobblers contest

Art Gobblers contest

5,520.95 USDC • 2 total findings • Code4rena • wagmi

#5

high

Can Recover Gobblers Burnt In Legendary Mint

medium

Wrong balanceOf user after minting legendary gobbler

Y2k Finance contest

Y2k Finance contest

161.88 USDC • 1 total finding • Code4rena • wagmi

#36

high

Users who deposit in one vault can lose all deposits and receive nothing when counterparty vault has no deposits

PartyDAO contest

PartyDAO contest

82.48 USDC • Code4rena • wagmi

#54

FEI and TRIBE Redemption contest

FEI and TRIBE Redemption contest

33.58 USDC • Code4rena • wagmi

#14

Nouns Builder contest

Nouns Builder contest

100.11 USDC • 2 total findings • Code4rena • wagmi

#88

medium

Founders can receive less tokens that expected

medium

Truncation in casting can lead to a founder receiving all the base tokens

Aug '22

Nouns DAO contest

Nouns DAO contest

52.1 USDC • Code4rena • wagmi

#38

FIAT DAO veFDT contest

FIAT DAO veFDT contest

107.61 USDC • 1 total finding • Code4rena • wagmi

#34

medium

ERROR IN UPDATING **_checkpoint** IN THE **increaseUnlockTime** FUNCTION

Foundation Drop contest

Foundation Drop contest

104.64 USDC • 1 total finding • Code4rena • wagmi

#22

medium

Possible to bypass saleConfig.limitPerAccount

Mimo August 2022 contest

Mimo August 2022 contest

67.51 USDC • Code4rena • wagmi

#40

Jun '22

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

325.9 USDC • 1 total finding • Code4rena • wagmi

#26

high

Calling `unstake()` can cause locked funds