Security Researcher
Guarding the chain, one slot at a time.
High
Total
Medium
Total Earnings
#844 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Jul '25
63.53 USDC • Sherlock • 0xShoonya
#42
Jun '25
3,015.78 USDC • 2 total findings • Sherlock • 0xShoonya
#5
medium
Permanent Lockout from Vault Auto-Deployment due to Stale State
Unbounded-Loop DoS in `VotingPowerProviderLogic`
24.32 USDC • 2 total findings • Sherlock • 0xShoonya
#45
high
Unauthorized fund claim for Solana cross-chain refunds via flawed recipient Determination
Users' assets sent to Bitcoin will be permanently lost if the cross-chain transfer reverts.
May '25
599.26 USDC • Sherlock • 0xShoonya
#14
Findings not publicly available for private contests.
Jan '25
0 USDC • 1 total finding • Code4rena • honey-k12
#12
Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions
Dec '24
0.38 USDC • 1 total finding • Code4rena • honey-k12
#65
Incorrect listing type validation bypasses enforcement of minimum purchase amount
0.01 OP • 1 total finding • Sherlock • 0xShoonya
Wrong Price Staleness Check in `currentValue()` Causes Outdated Prices to be used in the Protocol
#36
Minting zero tokens when underlyingToken is not Ether in cashIn()
Nov '24
96.48 USDC • 2 total findings • Code4rena • honey-k12
#21
`withdraw_liquidity` lacks slippage protection
Liquidity providers can lose tokens due to disproportionate deposits not being properly handled
27.05 USDC • Code4rena • honey-k12
#80
Oct '24
421.53 USDC • 1 total finding • Sherlock • 0xShoonya
Incorrect encoding of `questionId` field in `hashProposal` function breaks `EIP-712` compatibility
Jul '24
2.20 USDC • 1 total finding • Sherlock • 0xShoonya
#53
First liquidity provider of a stable pair can DOS the pool
Apr '24
1.89 USDC • 3 total findings • Code4rena • honey-k12
#52
Incorrect withdraw queue balance in TVL calculation
Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps
Lack of slippage and deadline during withdraw and deposit
10.49 USDC + NOYA stars • 2 total findings • Code4rena • honey-k12
#93
Missing calls to `_updateTokenInRegistry` leads to incorrect state of tokens in registry
`Keepers` does not implement EIP712 correctly on multiple occasions
Feb '24
0.04 USDC • 1 total finding • Code4rena • honey-k12
#185
Can mint NFT with the desired attributes by reverting transaction