https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/ee7cae51-a807-4137-9a63-fe57aaa3c92c.jpeg

0xGondar

Security Researcher

Contact Me

High

15

Total

Medium

12

Total

$739.00

Total Earnings

#1397 All Time

12x

Payouts

regular

1x

Top 10

regular

5x

Top 25

regular

6x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

Jul '25

succinct-network

succinct-network

298.24 USDC • 1 total finding • Cantina • 0xGondar

#19

high

Finding not yet public.

Mar '25

Crestal Network

Crestal Network

0.01 USDC • 1 total finding • Sherlock • 0xGondar

#12

high

Unprotected payWithERC20 Function allows complete theft of tokens

Feb '25

THORWallet

THORWallet

0.35 USDC • 1 total finding • Code4rena • 0xGondar

#8

high

MergeTgt has no handling if TGT_TO_EXCHANGE is exceeded during the exchange period

Core Contracts

Core Contracts

185.20 usdc • 16 total findings • CodeHawks • 0xgondar

#106

high

Wrong amount is minted to user when they deposit into the lending pool

high

Faulty Gauge Weight Update Formula: Voting Power Delta Not Considered Leading to Arithmetic Underflow and Vote Weight Inconsistency

high

Multiple Delegation by Double Spending Boosts and Lack of Delegation Tracking in BoostController Contract

high

Delegation Boost Not Usable by Delegatees

high

Multiple issues from unnecessary balance increase calculation in DebtToken.mint

high

Boost Miscalculation Leads to Excess Distribution

medium

Incorrect Return Values and Double Scaling in `RToken.burn` Function Leads to Denial of Service

medium

There is no logic checking for RAACNFT price staleness before minting it

medium

Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations

medium

Proposal Front-Running via Predictable Salt in `TimelockController::scheduleBatch`

medium

Users Cannot Remove Their Own Boost Delegation, Causing Potential Lock-In

medium

closeLiquidation within LendingPool does not allow partial repayments, which can cause massive losses to users within edge case

medium

Portion of revenue to be distributed for gauges remains undistributed

low

`mint` function in RToken contract doesn't return the correct expected values, leading to emission of ReserveLibrary `Deposit` event and LendingPool `Deposit` event with incorrect values.

low

Irreversible emission cap reduction in BaseGauge

low

Hardcoded Emission Values Lead to Incorrect Reward Calculations

Jan '25

Next Generation

Next Generation

3.65 USDC • 1 total finding • Code4rena • 0xGondar

#14

high

Cross-Chain Signature Replay Attack Due to User-Supplied `domainSeparator` and Missing Deadline Check

daao-contracts

daao-contracts

5.08 USDC • 2 total findings • Cantina • 0xGondar

#86

high

Finding not yet public.

high

Finding not yet public.

Plaza Finance

Plaza Finance

0.23 USDC • 1 total finding • Sherlock • 0xGondar

#99

medium

Auction bidding will be bricked for everyone by blacklisted user

Dec '24

Alchemix Transmuter

Alchemix Transmuter

11.67 op • 1 total finding • CodeHawks • 0xgondar

#27

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

SecondSwap

SecondSwap

4.28 USDC • 1 total finding • Code4rena • 0xGondar

#54

medium

Creator of one vesting plan can affect vesting plans created by other users.

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

0.18 OP • 1 total finding • Sherlock • 0xGondar

#66

high

Arbitrary Usda/Usdt Price Manipulation Allows Usdt Drain

Lambo.win

Lambo.win

230.47 USDC • 3 total findings • Code4rena • 0xGondar

#15

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

medium

Since the cost of launching a new pool is minimal, an attacker can maliciously consume VirtualTokens.

medium

Users can prevent protocol from rebalancing for his gain and cause loss of funds for protocol and its users

Oct '24

Dria

Dria

0.32 USDC • 1 total finding • CodeHawks • 0xgondar

#72

high

Subtraction in `variance()` will revert due to underflow