https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/c708b1d2-7bbd-40b2-9b85-538761b50492.jpg

0xShoonya

Security Researcher

Solidity and Rust

Contact Me

High

3

Total

Medium

18

Total

$6.67K

Total Earnings

#741 All Time

11x

Payouts

gold

1x

1st Places

regular

3x

Top 10

regular

5x

Top 25

All

Sherlock

Aug '25

USG - Tangent

USG - Tangent

2,095.58 USDC • 6 total findings • Sherlock • 0xShoonya

gold

high

Incorrect post-expiry PT pricing leads to inflated collateral value

medium

`ZappingProxy` cannot receive ETH refunds resulting in failed zaps

medium

Incompatibility of zap flow with share-based tokens due to transfer amount rounding

medium

Tokens will be stuck in `vsTAN` contract because of precision loss when calculating reward rate

medium

Permanent loss of rewards due to emission streaming with no stakers

medium

Revert in `_computeIR` due to precision loss in interest rate curve calculation

Jul '25

Malda

Malda

0.23 USDC • 1 total finding • Sherlock • 0xShoonya

#46

medium

Incorrect max Transfer size enforcement due to stale `TransferInfo` in `sendMsg`

Mellow Flexible Vaults

Mellow Flexible Vaults

524.62 USDC • 5 total findings • Sherlock • 0xShoonya

#19

high

`checkSignatures` counts duplicate signers toward the approval threshold

medium

Incorrect fenwick tree index usage leads to DOS in `cancelDepositRequest`

medium

ETH redemptions via `SignatureRedeemQueue` are broken due to missing `receive` function

medium

Incorrect logic in `ShareManager.updateChecks` blocks transfers from whitelisted senders when `hasTransferWhitelist` is enabled

medium

Single wei deficit in `stETH` deposit DoS's entire vault pipeline

DeBank

DeBank

63.53 USDC • Sherlock • 0xShoonya

#42

Notional Exponent

Notional Exponent

137.53 USDC • 2 total findings • Sherlock • 0xShoonya

#31

medium

Hardcoded WETH Address in `Constants.sol`

medium

Incorrect chain-specific logic for convex integration prevents deployment on Arbitrum and Base

Jun '25

Symbiotic Relay

Symbiotic Relay

2,796.16 USDC • 2 total findings • Sherlock • 0xShoonya

#5

medium

Permanent Lockout from Vault Auto-Deployment due to Stale State

medium

Unbounded-Loop DoS in `VotingPowerProviderLogic`

DODO Cross-Chain DEX

DODO Cross-Chain DEX

24.32 USDC • 2 total findings • Sherlock • 0xShoonya

#45

high

Unauthorized fund claim for Solana cross-chain refunds via flawed recipient Determination

medium

Users' assets sent to Bitcoin will be permanently lost if the cross-chain transfer reverts.

May '25

Native Smart Contract V2

Native Smart Contract V2

599.26 USDC • Sherlock • 0xShoonya

#14

Findings not publicly available for private contests.

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

0.01 OP • 1 total finding • Sherlock • 0xShoonya

#65

medium

Wrong Price Staleness Check in `currentValue()` Causes Outdated Prices to be used in the Protocol

Oct '24

predict.fun lending market

predict.fun lending market

421.53 USDC • 1 total finding • Sherlock • 0xShoonya

#5

medium

Incorrect encoding of `questionId` field in `hashProposal` function breaks `EIP-712` compatibility

Jul '24

Velocimeter

Velocimeter

2.20 USDC • 1 total finding • Sherlock • 0xShoonya

#53

medium

First liquidity provider of a stable pair can DOS the pool