oakcobalt

Ranking #6 in Code4rena 2024. 40+ audits. Specialized in solidity, Rust, and CosmWasm audit.

Available
2 years experience
Vetted

Programming Languages

SolidityRustGo

Expertise & Skills

LendingAMMPerpetualsCross-chainStaking

Let Us Help You Connect

Our team can assist with project requirements, timeline coordination, and finding the perfect match

Portfolio & Experience

Detailed audit history and technical expertise

oakcobalt Security Research

Reach out via telegram, or X

Ranking

  • x5 First place
  • x19 Top 3
  • #6 on Code4Rena 2024

Audit Experience

See below a curated list of public contest or private audits:

Findings

See below some highlights of findings:

ProtocolTypeReportKey Findings & Learnings
Superposition - Concentrated liquidity AMM - 2024.09Rust, ERC20, Styluslink- Confirmed findings: 4 High 5 Medium - Example Finding: High: swapOut functions have invalid slippage check, causing user loss of funds
BendDao - Composable lending and leveraging - 2024.08Solidity, ERC20, ERC721link- Confirmed findings: 5 High 10 Medium - Example Finding: Medium: Incorrect accounting of utilization, supply / borrow rates due to vulnerable implementation in IsolateLogic::executeIsolateLiquidate
Gondi - NFT lending,capital efficient loan primitive - 2024.04Solidity, ERC20, ERC721link- Confirmed findings: 5 High 10 Medium - Example Finding: High: Incorrect circular array check in _updatePendingWithdrawalWithQueue flow , causing received funds added to the wrong queues
Canto - L1 Blockchain, omnichain messaging - 2024.03Solidity, LayerZerolink- Confirmed findings: 2 High 2 Medium - Example Finding: Medium: asdRouter.sol is at risk of DOS due to vulnerable implementation of NOTE address
Gitcoin Passport - Identify staking - 2024.04Solidity, ERC20link- Confirmed findings: 2 High - Example Finding: High: userTotalStaked invariant will be broken due to vulnerable implementations in release()
zkSync Era - L2 scaling, briding, migration - 2024.03Solidity, Yullink- Confirmed findings: 3 Medium - Example Finding: Medium: User might be able to double withdraw during migration
Thruster - Dex, Uniswap v2/v3 fork - 2024.02Solidity, Blastlink- Confirmed findings: 3 Medium - Example Finding: Medium: Lottery winners might lose some of their entitled prize due to vulnerable implementation in claimPrizesForRound()
HydraDX - Dex on polkadot, omnipool - 2024.02Rust, Substratelink- Confirmed findings: 3 Medium - Example Finding: Medium: In Omnipool, Users will be over charged withdrawal_fee when the withdrawal is safe
Salty.IO - Dex, autromqtic arbitrage, stablecoin - 2024.01Solidity, ERC20link- Confirmed findings: 1 High 5 Medium - Example Finding: High: USDS repaid will not be transferred to Liquidizer, but Liquidizer will still burn the amount of USDS in upkeep, causing Liquidizer always draining protocol owned liquidity
ZetaChain - L1 blockchain, crosschain - 2023.12Solidity, Go, Cosmo-sdklink- Confirmed findings: 2 High 5 Medium - Example Finding: High: In ZetaTokenConsumerTrident. strategy.sol, swapping zeta for other tokens will always revert due to incorrect exactInputSingle router method being used
Shell - Dynamic Liquidity Concentration AMMs - 2023.08Solidity, ERC-1155link- Confirmed findings: 1 High - Example Finding: High: checkBalances can be bypassed, resulting in untested and unsafe parameters of the bonding curve being used
Basin - Composable AMMs - 2023.07Solidity, ERC-20link- Confirmed findings: 1 High 1 Medium - Example Finding: Medium: Single hardcoded cap used for multiple tokens in a pump causing some assets to be more stale, while having no effects on other stable assets
Ajna - Lending and borrowing with no price feeds - 2023.06Solidity, ERC-20link- Confirmed findings: 1 Medium - Example Finding: Medium: Lenders lose interests and pay deposit fees due to no slippage control
Iron Bank - Lending and borrowing - 2023.05Solidity, ERC-20link- Confirmed findings: 3 Medium - Example Finding: Medium: Wrong Price will be Returned When Asset is PToken for WstETH
Teller - Lending and borrowing - 2023.04Solidity, ERC-20link- Confirmed findings: 1 Medium - Example Finding: Medium: Premature Liquidation When a Borrower Pays early