Security Researcher
High
Total
Medium
Total Earnings
#1162 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
Sep '25
76.81 USDC • 2 total findings • Sherlock • werulez99
#6
medium
Removing a reward token doesn’t reset state and later re-adding lets late stakers steal historical rewards
Malicious callers can throttle USDC/USDT/WBTC rewards by spamming getRewardFor.
Mar '25
610.41 USDC • 1 total finding • Code4rena • HaidutiSec
Anyone can DOS handleReallocation over and over
Feb '25
228.43 USDC • 2 total findings • Cantina • merulz99
#17
high
Jan '25
1,004.24 USDC • 1 total finding • Sherlock • werulez99
#13
#Collateral level Inflation vulnerability
Feb '24
2.06 USDC • 1 total finding • Code4rena • Merulez99
#157
Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win