https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

zraxx

High

14

Total

Medium

1

Solo

9

Total

$22.67K

Total Earnings

#330 All Time

16x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

bronze

3x

3rd Places

All

Sherlock

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

77.25 USDC • 2 total findings • Sherlock • zraxx

#9

high

Most of the users' reward will be lost due to frequent calls to notifyRewardAmount and loss of precision.

medium

Incorrect checking logic in the function _resetVestingPlans will cause the addLiquidity function to fail.

Feb '25

Yieldoor

Yieldoor

283.95 USDC • 2 total findings • Sherlock • zraxx

#7

high

The function liquidatePosition incorrectly calculates borrowedValue, causing borrowedValue to be abnormally large.

medium

Leverager#withdraw use the wrong repayFromWithdraw when `borrowed == up.token1`

Jan '25

Plaza Finance

Plaza Finance

1,333.92 USDC • 3 total findings • Sherlock • zraxx

#8

high

The pool contract will be drained by the attacker due to incorrect multiplier settings.

high

By splitting large purchases and redemptions into multiple smaller amounts, users can get more returns.

medium

Potential Token Transfer Failure in _removeBid Function

Sep '24

Flayer

Flayer

607.29 USDC • 2 total findings • Sherlock • zraxx

#26

high

`relist` does not set the create time of the listing, so the attacker can set the create time to the future.

high

When relisting a floor item listing, listingCount is not increased, causing listingCount can be underflowed.

MorphL2

MorphL2

1,565.25 USDC • 2 total findings • Sherlock • zraxx

#12

medium

When a staker is removed, the previous unclaimed commission rewards will not be available for claiming.

medium

`getStakersFromBitmap` cannot reach stakerSet[254], resulting in the user being unable to be slashed

May '24

Gamma - Locked Staking Contract

Gamma - Locked Staking Contract

133.81 USDC • 1 total finding • Sherlock • zraxx

bronze

medium

Users cannot set a deadline for earlyExitById/exitLateById, which may cause users to lose many assets.

PoolTogether: The Prize Layer for DeFi

PoolTogether: The Prize Layer for DeFi

1,309.31 USDC • 2 total findings • Sherlock • zraxx

#10

high

When the total Draw Auction Rewards exceeds availableRewards, `finishDraw` will fail.

medium

By claiming prizes at the canary tiers, malicious users can reduce the claim fee at other tiers

Mar '24

RadicalxChange

RadicalxChange

1.18 USDC • 1 total finding • Sherlock • zraxx

bronze

high

The function _cancelAllBids does not check whether the bidder is the highestBidder

WagmiLeverage V2

WagmiLeverage V2

9,500 USDC • 1 total finding • Sherlock • zraxx

gold

medium

When the amout of token acquired by a flash loan exceeds the expected value, the callback function will fail.

WOOFi Swap

WOOFi Swap

127.48 USDC • 1 total finding • Sherlock • zraxx

#9

medium

In the function _handleERC20Received, the fee was incorrectly charged

Feb '24

Real Wagmi #2 Update

Real Wagmi #2 Update

5,538.46 USDC • 1 total finding • Sherlock • zraxx

silver

high

When using the `borrow` function to update the `BorrowingInfo`, the previously accumulated fees were not distributed in time.

Rio Network

Rio Network

5.57 USDC • 1 total finding • Sherlock • zraxx

#31

high

The function `settleEpochFromEigenLayer` does not update `currentEpochsByAsset`, resulting in subsequent settlement failed.

Jan '24

LooksRare YOLO

LooksRare YOLO

17.38 USDC • 1 total finding • Sherlock • zraxx

#7

high

In the function _depositETH, there is no check whether depositAmount is equal to 0, which allows malicious users to perform draws at a cost of 0 and maliciously increase the count of deposit.

Truflation

Truflation

1,894.28 USDC • 1 total finding • Sherlock • zraxx

bronze

high

In function `cancelVesting`, the variable `userVesting` is type of memory, which will cause the assignment to locked to be invalid.

Nov '23

Nouns Builder

Nouns Builder

21.94 USDC • 1 total finding • Sherlock • zraxx

#9

high

The first founder's share will be lost by 1% when reservedUntilTokenId>=100

Oct '23

Real Wagmi #2

Real Wagmi #2

257.41 USDC • 1 total finding • Sherlock • zraxx

#14

high

In `takeOverDebt`, wrong parameter `borrowingKey` is used to call `_addKeysAndLoansInfo`