Skip to content
View t0x1cC0de's full-sized avatar

Block or report t0x1cC0de

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
t0x1cC0de/README.md

πŸ‘‹ t0x1c's info, stats & security audits

I weed out t0x1c bugs from codebases.

  • πŸ‘¨β€πŸ’Ό Security Specialist @ Sherlock

Find me on:


Highlights

Total Podium Finishes: 10

Rank Frequency
#1 πŸ₯‡ 2
#2 πŸ₯ˆ 4
#3 πŸ₯‰ 4
#4 - #10 πŸ† 11

πŸ† Ranked #4 on Code4rena's 90-day leaderboard in April 2024.


πŸ” Lifetime Findings : 156 $\rightarrow$ 43 Highs, 113 Mediums


πŸ’° Major Contest Wins:

Protocol Rank Amount Domain
Taiko πŸ₯ˆ #2 $19,343 Based Rollup, L2, Cross-Chain, Bridge
Salty.io Mitigation Review πŸ₯‡ #1 $12,542 DEX, AMM
Numa Money πŸ₯‰ #3 $7,318 LST-backed synthetics trading protocol
Wise Lending πŸ† #9 $7,145 Decentralized liquidity market
Salty.io πŸ₯ˆ #2 $5,264 DEX, AMM

🎯 Most Impactful Findings:

Finding Severity & Dups Protocol Domain
Incorrect liquidation mechanics either causes revert on liquidation due to insufficient seizeTokens or causes transition into bad debt Med; Unique Numa Money LST-backed synthetics trading protocol
Deprecated markets allow profitable exploitation of bad debt liquidations Med; Unique (Self-dup) Numa Money LST-backed synthetics trading protocol
Invocation delays are not honoured when protocol unpauses Med; Unique Taiko Based Rollup, L2, Cross-Chain, Bridge
Prover loses funds even if proven right after multiple contests High; 1 dup Taiko Based Rollup, L2, Cross-Chain, Bridge
Protocol does not check inside GuardianProver::approve() if all the guardians are approving the same proof Med; 1 dup Taiko Based Rollup, L2, Cross-Chain, Bridge
Adding liquidity with useZapping = true allows user to steal funds Med; Unique Salty.io Mitigation Review DEX, AMM
All reentrancy guards can be bypassed since sendingProgress and sendingProgressAaveHub variables inside _sendValue() can be reset High; 1 dup Wise Lending Decentralized liquidity market
User's attempt to deposit & withdraw reverts due to the calculation style inside _calculateShares() Med; 1 dup Wise Lending Decentralized liquidity market

πŸ›‘οΈ Private Audits

Year Month Audit Report Domain Language
2024 Apr Salty.IO DEX, AMM Solidity

πŸ‘¨β€πŸ’Ό Pashov Audit Group

Year Month Audit Report Domain Language
2025 Jun Reserve DeFi Solidity

πŸ† Contests

Year Month Wins
2025 Jun - LayerEdge [My Submissions] [Official Report] [Rank 5 / 1156]

- RAAC [My Submissions] [Official Report] [Rank 14 / 419]

- Starknet Staking Part 2 [Official Report] [Rank 18 / 41]
2025 May - Silo Mitigation Review [Rank 1 / 3] (Shared)

- Aegis [My Submissions] [Official Report] [Rank 4 / 429]
2025 Apr - Nudge.xyz [My Submissions] [Official Report] [Rank 3 / 1078]

- Usual Labs [My Submissions] [Official Report] [Rank 4 / 224]

- PinLink [My Submissions] [Official Report] [Rank 2 / 424]

- Symmio [My Submissions] [Official Report] [Rank 12 / 461]

- Gamma [My Submissions] [Official Report] [Rank 5 / 108]

- Silo Finance [My Submissions] [Official Report] [Rank 2 / 1136]
2025 Mar - Rova [My Submissions] [Official Report] [Rank 3 / 397]
2025 Feb - Concrete [My Submissions] [Official Report] [Rank 5 / 189]

- Plaza [My Submissions] [Official Report] [Rank 22 / 2471]

- IQAI [My Submissions] [Official Report] [Rank 5 / 671]
2025 Jan - Numa [My Submissions] [Official Report] [Rank 3 / 255]
2024 Dec - Ethos [My Submissions] [Official Report] [Rank 4 / 395]

- Oku [My Submissions] [Official Report] [Rank 31 / 309]
2024 Jul - Nov - Much needed break !!
2024 Jun - BakerFi [My Submissions] [Official Report] [Rank 4 / 5]

- Renzo [My Submissions] [Official Report] [Rank 36 / 122]

- Euler-v2 [My Submissions] [Official Report] [Rank 36 / 610]
2024 May - Hodl Money (C4 Private Invitational Audit) [Rank 3 / 5]

- Zivoe [My Submissions] [Official Report] [Rank 16 / 358]
2024 Apr - WiseLending [My Submissions] [Official Report] [Rank 9 / 36]

- Taiko [My Submissions] [Official Report] [Rank 2 / 69]
2024 Mar - Mitigation Audit - Salty.IO [My Submissions] [Official Report] [Rank 1 / 3]
2024 Feb - The Standard [My Submissions] [Official Report] [Rank 6 / 100]

- Salty.IO [My Submissions] [Official Report] [Rank 2 / 177]
2023 Dec - Canto [My Submissions] [Official Report] [Rank 98 / 120]

- Nextgen [My Submissions] [Official Report] [Rank 12 / 242]
2023 Nov - Ditto - DittoETH [My Submissions] [Official Report] [Rank 7 / 81]

- Wildcat [My Submissions] [Official Report] [Rank 32 / 131]
2023 Sep - Foundry DeFi Stablecoin CodeHawks Audit Contest [My Submissions] [Official Report] [Rank 11 / 229]

- Sparkn [My Submissions] [Official Report] [Rank 87 / 202]

Popular repositories Loading

  1. int0x1cated-Earnings-and-Progress int0x1cated-Earnings-and-Progress Public

    My Progress & Earnings as a Blockchain Security Researcher

    1 1

  2. t0x1cC0de t0x1cC0de Public

    My portfolio