Security Researcher
have fun
High
Total
Medium
Total Earnings
#805 All Time
Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Code4rena
Cantina
CodeHawks
Feb '25
238.32 USDC • Sherlock • zhuying
#24
Jan '25
15.29 usdc • CodeHawks • zhuying
#21
Dec '24
11.67 op • 2 total findings • CodeHawks • zhuying
#26
medium
not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.
low
Old router retains token allowance after update
1,987.07 USDC • Code4rena • zhuying
Jul '24
416.11 USDC • 3 total findings • CodeHawks • zhuying
#7
Anyone can call the fallbackFunction because of missing authorization control
Protocol not fully compliant with `EIP-7579`
`Nexus.validateUserOp()` violates the EIP-4337 specification
May '24
81.46 USDC • 1 total finding • CodeHawks • zhuying
#34
High Risk Denial-of-Service (DoS) Vulnerability in ERC1155 Token Minting Process.
198.3 USDC • 1 total finding • Cantina • zhuying
#14
Apr '24
8.59 USDC • 2 total findings • Code4rena • zhuying
#94
Value of kerosene can be manipulated to force liquidate users
Incorrect deployment / missing contract will break functionality
748.76 USDC • 1 total finding • CodeHawks • zhuying
```LibWstethEthOracle::getWstethEthPrice``` returns wrong ```wstETH/ETH``` price in some conditions impacting system operations
Feb '24
363.37 USDC • 1 total finding • Sherlock • zhuying
#5
The functions about ```permit``` won't work and always revert
Jan '24
2.64 USDC • 1 total finding • Sherlock • zhuying
#9
high
[M-01] The burn function will break the claim function
Oct '23
0 USDC • 1 total finding • Code4rena • zhuying
#115
Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime