https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/f664c57c-61ef-4537-bf13-f33d18965b6b.jpg

0xRajeev

Security Researcher

Secureum = Security + Ethereum Founder: @0xRajeev Discord: https://t.co/m9fMLfXhEU Newsletter: https://t.co/A3ypVExpzQ

Contact Me

High

10

Solo

60

Total

Medium

4

Solo

70

Total

$329.77K

Total Earnings

#26 All Time

28x

Payouts

gold

8x

1st Places

silver

4x

2nd Places

bronze

6x

3rd Places

All

Sherlock

Code4rena

May '21Jun '21Jul '21Aug '21Sep '21Oct '22

Oct '22

Astaria

Astaria

39,039.66 USDC • 35 total findings • Sherlock • 0xRajeev

gold

high

Triggering liquidations ahead of expected time leads to loss and lock of funds

high

Incorrect operator in `AstariaRouter.isValidRefinance` can lead to borrower loss and potential liquidation

high

Loans can exceed the maximum potential debt leading to vault insolvency and possible loss of LP funds

high

Payments and liquidations of multiple liens will revert and can be exploited, causing payer fund loss

high

Public vault depositors will receive fewer vault shares until the first payment

high

Epochs can be progressed during ongoing auctions to cause LP fund loss and collateral lockup

high

Anyone can deposit and mint withdrawal proxy shares to capture distributed yield from borrower interests

high

Auction bid that partially pays back an expired lien will revert

high

Lien buyout with new terms does not update the slope of public vaults

high

A malicious lien buyer can DoS to cause fund loss/lock

high

`VaultImplementation._validateCommitment` may prevent liens that satisfy their terms of `maxPotentialDebt`

high

Auctions with remaining liens will always revert causing loss of funds for the highest bidder and stuck collateral

high

A malicious lien owner can exploit a reentrancy to steal LP funds

high

`LiquidationAccountant.claim()` can be called by anyone causing vault insolvency

high

A payment made towards multiple liens causes the borrower to lose funds to the payee

high

Purchaser of a lien token may not receive payments

high

Lien count per epoch is not updated ultimately locking the collateralized NFT

high

`LienToken.buyoutLien` will always revert

high

Public vaults can become insolvent because of missing `yIntercept` update

high

Canceling an auction will result in a loss of borrower funds towards initiator fees

high

Canceling an auction with 0 bids will only partially pay back the outstanding debt

high

Canceling an auction does not refund the current highest bidder

high

`commitToLiens` always reverts

medium

Loan duration can exceed the end of the next epoch

medium

Buyouts of shorter duration liens can lead to the loss of borrower funds

medium

Minting public vault shares while the protocol is paused can lead to LP fund loss

medium

Incorrect calculation in `PublicVault.timeToEpochEnd()` causes loss of LP funds and lock of borrower collateral

medium

Auctions run for less time than intended

medium

Incorrect `LienToken.changeInSlope` calculation can lead to vault insolvency

medium

Any excess payment by the borrower towards a lien is not refunded leading to a loss of borrower funds

medium

`LienToken.createLien` may prevent liens that satisfy their terms of `maxPotentialDebt`

medium

`AstariaRouter.commitToLiens` will revert if the protocol fee is enabled

medium

Enforcing the maximum auction duration fails, leading in potential loss of funds to LPs

medium

Extension logic incorrectly extends the auction by an additional amount of existing duration

medium

Outstanding debt is not guaranteed to be covered by auctions

Aug '22

Nouns DAO contest

Nouns DAO contest

35.44 USDC • Code4rena • 0xRajeev

#41

Aug '21

Yield micro contest #1

Yield micro contest #1

2,366.82 USDC • Code4rena • 0xRajeev

#4

Jul '21

Jun '21

May '21

Apr '21

LarvaLabs Meebits Contest

LarvaLabs Meebits Contest

15,307.48 USDC • Code4rena • 0xRajeev

gold
Based Loans contest

Based Loans contest

4,523.84 USDC • Code4rena • 0xRajeev

#4

Maple Finance contest

Maple Finance contest

5,382.1 USDC • Code4rena • 0xRajeev

#4

Feb '21

ElasticDAO contest

ElasticDAO contest

5,970.13 ETH • Code4rena • 0xRajeev

bronze
Slingshot Finance contest

Slingshot Finance contest

8,491.58 USDC • Code4rena • 0xRajeev

gold