Hey! M4ze here β Iβm a Web3 Security Researcher.
Rust, Solidity, even Vyper β I find bugs in any language. Ethereum, Solana, Cosmos β I find bugs in any stack.
| Metric | Value |
|---|---|
| Total Earnings | $5.05K |
| Total Contests | 826 (All Time) |
| Total Payouts | 12Γ |
| Top 10 Finishes | 3Γ |
| Top 25 Finishes | 6Γ |
| Top 50 Finishes | 7Γ |
| Contest | Platform | Earnings | Rank | Key Findings |
|---|---|---|---|---|
| Audit 507 | Code4rena | 323.07 USDC | #12 | β |
| Alchemix V3 | Cantina | 47.7 USDC | #75 | High: (Private) Medium: (Private) |
| Contest | Platform | Earnings | Rank | Key Findings |
|---|---|---|---|---|
| Cabal Liquid Staking Token | Code4rena | 249.98 USDC | #8 | Medium: Desynchronization of internal accounting vs actual staked INIT amounts allows over-minting of sxINIT tokens |
| Kinetiq | Code4rena | 9.35 USDC | #33 | Medium: Inconsistent state restoration in cancelWithdrawal() leads to stale user balances |
| Staking Part 2 | CodeHawks | 4103.92 USDC | #7 | β |
| Mighty Contracts | Cantina | 0.07 USDC | #115 | High: (Private) |
| Contest | Platform | Earnings | Rank | Key Findings |
|---|---|---|---|---|
| Forte: Float128 Solidity Library | Code4rena | 49.20 USDC | #23 | High: ln() accepts invalid non-positive inputsHigh: sqrt() silently reverts entire control flow on zero-value packed float |
| Contest | Platform | Earnings | Rank | Key Findings |
|---|---|---|---|---|
| Virtuals Protocol | Code4rena | 35.33 USDC | #56 | Medium: Slippage check at execution time provides no real protection as it reads post-trade price |
| Liquidity Management | CodeHawks | 0.66 USDC | #55 | Low: Incorrect token-price validation in KeeperProxy |
| Core Contracts | CodeHawks | 41.64 USDC | #201 | High: ZENO redemption yields negligible USDC value High: Decimal mismatch in Auction::buy() leads to massive overpaymentHigh: Flawed TWAP fee distribution High: Hard-coded FX rate corrupts deposits/redemptions Medium: Liquidations blocked by strict debt check Medium: Missing freshness check for RAACNFT priceMedium: Boost multiplier always returns max value Low: Incorrect timestamp tracking in RAACHousePriceLow: Inconsistent voting-power logic |
| Contest | Platform | Earnings | Rank | Key Findings |
|---|---|---|---|---|
| Aave DIVA Wrapper | CodeHawks | 0.04 USDC | #9 | Low: Misordered constructor parameters in AaveDIVAWrapper |
| Ignite | CodeHawks | 121.92 USDC | #18 | β |