https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

0xAman

Security Researcher

Contact Me

High

11

Total

Medium

11

Total

$4.79K

Total Earnings

#810 All Time

15x

Payouts

regular

1x

Top 10

regular

5x

Top 25

regular

12x

Top 50

All

Cantina

CodeHawks

May '25

alchemix-v3

alchemix-v3

245.64 USDC • 3 total findings • Cantina • 0xaman

#36

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Apr '25

mezo-monorepo

mezo-monorepo

106.87 USDC • 1 total finding • Cantina • 0xaman

#36

medium

Finding not yet public.

liquidity-book-vaults

liquidity-book-vaults

138.45 USDC • 4 total findings • Cantina • 0xaman

#23

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Sep '24

Liquid Staking

Liquid Staking

201.10 USDC • 5 total findings • CodeHawks • 0xaman

#27

medium

Remove splitter will always revert if there are some rewards left on splitter contract

low

Upgrading `OperatorVCS` Contract Will Fail

low

Upgrade Initialization Logic Will Never Execute Due to Incorrect Initializer Usage in CommunityVCS

low

No way to update unbonding and claim periods

low

Due To The `minWithdrawalAmount` check Users Who Want To Withdraw Wont Be Able To Queue Their Token Withdrawals On Some Amounts

Royco Protocol

Royco Protocol

42.34 USDC • 1 total finding • Cantina • 0xaman

#52

high

Finding not yet public.

symbioticfi-core

symbioticfi-core

1,211.51 USDC • 1 total finding • Cantina • 0xaman

#10

medium

Finding not yet public.

Aug '24

Tadle

Tadle

162.88 USDC • 4 total findings • CodeHawks • 0xaman

#39

high

TokenManager - Unlimited withdraw

high

Native token withdrawal fails until manually approved

high

[H-4] The function `PreMarkets::listOffer` charges an incorrect collateral amount, allowing users to manipulating collateral rates and drain the protocol's funds

low

The user will be able to close Bid Offer even in case if marketplace is not in BidSettling

Jul '24

ArkProject: NFT Bridge

ArkProject: NFT Bridge

249.56 USDC • 3 total findings • CodeHawks • 0xaman

#28

high

`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`

low

Incorrect function signatures in `_callBaseUri` break `baseURI` functionality

low

function erc721Metadata returns empty base uri instead of token uris

Zaros Part 1

Zaros Part 1

20.64 USDC • 3 total findings • CodeHawks • 0xaman

#77

high

Market Disruption and Financial Loss Post-Liquidation

medium

A malicious User can DOS all offchain orders making them unexecutable and leaving the protocol in an insolvent state. Also all offchain Trades can also be DOSed for honest parties that do not meet the fillorder requirements (no try and catch)

low

Liquidation of accounts collateral not posible because some chainlink price feed doesn't exist or are marked as medium risk by chainlink

TempleGold

TempleGold

21.05 USDC • 1 total finding • CodeHawks • 0xaman

#35

high

Incompatibility with Multisig Wallets in `TempleGold::send` Function

Jun '24

Pegasus

Pegasus

250 USDC • Cantina • 0xaman

#11

May '24

Sablier

Sablier

550.31 USDC • 3 total findings • CodeHawks • 0xaman

#11

medium

Use of CREATE method is suspicious of reorg attack

low

Cancelling a Merkle Lockup is only callable by `initialAdmin` even after `admin` had been modified

low

Stream sender is unable to cancel a stream with a pausable asset that is paused

Jan '24

Blast

Blast

528.81 USDC • 1 total finding • Cantina • 0xaman

#48

medium

Finding not yet public.

Dec '23

The Standard

The Standard

0.07 USDC • 1 total finding • CodeHawks • 0xaman

#102

high

Rewards can be drained because of lack of access control

Sep '23

DittoETH

DittoETH

1,057.48 USDC • 2 total findings • CodeHawks • 0xaman

#14

high

Previous NFT owner can burn NFT from the new owner

low

`onERC721Received()` callback is never called when new tokens are minted in Erc721Facet.sol