https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

zkillua

Security Researcher

Contact Me

High

10

Total

Medium

13

Total

$677.00

Total Earnings

#1423 All Time

7x

Payouts

regular

1x

Top 10

regular

1x

Top 25

regular

2x

Top 50

All

Sherlock

Code4rena

CodeHawks

Jul '25

DeBank

DeBank

3.05 USDC • Sherlock • zkillua

#102

Feb '25

Core Contracts

Core Contracts

97.88 usdc • 26 total findings • CodeHawks • DRUGstore

#144

high

Wrong amount is minted to user when they deposit into the lending pool

high

Users Can Overwrite Existing Locks in veRAACToken Resulting in Permanent Loss of Funds

high

`GaugeController` does not send funds to FeeCollector disrupting fees distribution and causing loss of funds

high

Multiple issues from unnecessary balance increase calculation in DebtToken.mint

high

Users can borrow more assets than they have deposited as collateral

high

Any attempt to liquidate a user will fail, because StabilityPool does not hold crvUSD during operational lifecycle

high

RToken is Not Interest Bearing Due to Broken Liquidity Index Calculation

high

Double Usage Index Scaling in StabilityPool Liquidation Inflates Required CRVUSD Balance

high

Incorrect Debt Scaling Leading to Protocol Solvency Risk

medium

`MAX_TOTAL_SUPPLY` Bypass in `veRAACToken` via `increase()` Function

medium

veRaac Token Constraint MAX_TOTAL_SUPPLY Can Be Bypassed. Vulnerability Disrupts Protocol Functionality and Undermines Governance Quorum.

medium

Incorrect DebtToken totalSupply Scaling Breaks Interest Rate Calculations

medium

Incorrect Return Values and Double Scaling in `RToken.burn` Function Leads to Denial of Service

medium

LendingPool deposits do not work with CurveVault due to lack of funds

medium

Users Can Lose Funds and Collateral by Repaying Loans After Liquidation Grace Period Expiry

medium

Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check

medium

Using balanceOf Instead of Voting Power

medium

Multiple Critical Calculation And Logic Errors in `RToken::mint/burn` Function

medium

There is no logic checking for RAACNFT price staleness before minting it

medium

`RToken::calculateDustAmount` are incorrectly calculated, leading to not be able to transfer the accrued dust amount

low

`mint` function in RToken contract doesn't return the correct expected values, leading to emission of ReserveLibrary `Deposit` event and LendingPool `Deposit` event with incorrect values.

low

Irreversible emission cap reduction in BaseGauge

low

Improper Lock State Updates: Misreported Locked Token Data infects Governance Participation, rewards distribution and Harms Protocol Trust.

low

Incorrect Initialization of minBoost in BaseGauge Constructor Breaks Core Contract Functionality

low

Missing Checkpoint Reset in `veRAACToken::emergencyWithdraw` Function

low

Missing Pause Functionality in veRAACToken Contract Can Be Abused When Emergency Withdrawal Mechanism Is Activated

Jan '25

IQ AI

IQ AI

551.36 USDC • 1 total finding • Code4rena • Zkillua

#10

medium

[M-3] Anyone can deploy a new `FraxSwapPair` with a Low fee incurring losses to the protocol

Aave v3.3

Aave v3.3

8.70 USDC • Sherlock • zkillua

#110

Nov '24

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

3.81 USDC • Sherlock • zkillua

#63

Debita Finance V3

Debita Finance V3

12.57 USDC • 1 total finding • Sherlock • zkillua

#49

medium

`extendedTime` calculation in `DebitaV3Loan::extendLoan` shall Cause denial of Service, due to overflow-underflow error.

Jun '24

Size

Size

0.05 USDC • 1 total finding • Code4rena • Zkillua

#62

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect