https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/6796c07a-2aac-4a0b-ab5c-d686aa9e41f0.jpg

0xSpearmint1

Security Researcher

smart contract security researcher

Contact Me

High

15

Total

Medium

14

Total

$66.05K

Total Earnings

#127 All Time

11x

Payouts

silver

2x

2nd Places

regular

6x

Top 10

regular

9x

Top 25

All

Sherlock

Cantina

Jan '25

Peapods

Peapods

51.22 USDC • 1 total finding • Sherlock • 0xSpearmint1

#27

medium

Double Debond Fee Application in `_calculateBasePerPTkn()`

Aave v3.3

Aave v3.3

3,930.55 USDC • Sherlock • 0xSpearmint1

#15

Dec '24

bima-money

bima-money

6,645.41 USDC • 3 total findings • Cantina • Spearmint

#7

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Nov '24

hyperlend

hyperlend

1,043.12 USDC • 1 total finding • Cantina • Spearmint

#11

high

Finding not yet public.

sorella-angstrom

sorella-angstrom

2,500 USDC • Cantina • Spearmint

#9

Sep '24

infinitypools

infinitypools

24,386.64 USDC • 5 total findings • Cantina • Spearmint

silver

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

instadapp-fluid

instadapp-fluid

1,900 USDC • Cantina • Spearmint

#5

Aug '24

zetachain-protocol

zetachain-protocol

218.96 USDC • 3 total findings • Cantina • Spearmint

#40

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

MakerDAO Endgame

MakerDAO Endgame

6,561.92 USDC • Sherlock • 0xSpearmint1

#18

May '24

PoolTogether: The Prize Layer for DeFi

PoolTogether: The Prize Layer for DeFi

6,445.57 USDC • 6 total findings • Sherlock • 0xSpearmint1

#5

high

Malicious user can take advantage of auto-accruing WETH in the PrizePool contract on blast to unfairly increase winning odds

medium

after the TWAB limit is reached, back-running a call to `withdraw` with a liquidation of yield is extremely profitable for the liquidator at the expense of all the other users in the vault

medium

An attacker can DOS liquidations once a vault is near the TWAB limit

medium

PUSH0 Opcode is not supported on linea chain

medium

Witnet does not support all the networks the protocol will be deployed on

medium

A malicious user can set their hook to a malicious implementation, so that claimers tx spends all the gas allocated and reverts

Mar '24

Smart-contracts

Smart-contracts

12,364.26 USDC • 10 total findings • Cantina • Spearmint

silver

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.