https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

iamnmt

Security Researcher

Contact Me

High

1

Solo

33

Total

Medium

35

Total

$26.81K

Total Earnings

#293 All Time

18x

Payouts

gold

1x

1st Places

silver

3x

2nd Places

bronze

2x

3rd Places

All

Sherlock

Code4rena

Cantina

CodeHawks

Aug '24Sep '24Oct '24Nov '24Jan '25Feb '25

Jan '25

reserve-index-dtf

reserve-index-dtf

$53.43 • 1 total finding • Cantina • 3n0ch

#8

medium

Finding not yet public.

Aug '24

ZeroLend One

ZeroLend One

$4,179.52 • 13 total findings • Sherlock • iamnmt

bronze

high

A NFT's `_balances` is not updated during liquidation will cause `_balances` and `_totalSupply` to report a stale value

high

Incorrect deduction of `accruedToTreasuryShares` from `totalSupply.supplyShares` in `executeMintToTreasury` will cause broken accounting, insolvency

high

`POOL_ADMIN_ROLE` can set a pool's `interestRateStrategyAddress` to a bad address to cause loss of funds to a vault

high

An attacker can hijack the `CuratedVault`'s matured yield

high

Incorrect conversion between debt shares and supply collateral shares will cause incorrect calculation of liquidation rewards or debt deduction

high

Wrong calculation in `PositionBalanceConfiguration#getSupplyBalance` when `liquidityIndex > ray` will cause broken accounting

medium

Different oracle's decimals will cause wrong calculation in `GenericLogic#calculateUserAccountData`

medium

Wrong implementation of `CuratedVault#reallocate` when `allocation.assets = 0` will cause unknown frontrunning donations can not be withdrawn

medium

`CuratedVault` is vulnerable to an inflation attack when 18 decimals token is used as an asset

medium

In `NFTPositionManager`, `_totalSupply` and `_balances` will be stale when `borrowIndex` and `liquidityIndex` are increased

medium

Missing a `updateInterestRates` step in `executeMintToTreasury`

medium

Hardcoded oracle's heartbeat in `Pool` will cause using stale price in case of short heartbeat oracle and DoS in case of long heartbeat oracle

medium

`borrowIndex` increases faster than `liquidityIndex` will cause the borrowers overpay their debt

Jul '24

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

$3,120.45 • 10 total findings • Sherlock • iamnmt

silver