https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

0xTheBlackPanther

Security Researcher

software engineer | security researcher | Discord: _theblackpanther

Contact Me

High

22

Total

Medium

53

Total

$58.37K

Total Earnings

#191 All Time

35x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

15x

Top 10

All

Sherlock

Cantina

CodeHawks

Nov '25

Layerbank - Nov 21st

Layerbank - Nov 21st

Collaborative Audit • Sherlock • 0xTheBlackPanther

May '25

jigsaw-contracts

jigsaw-contracts

78.3 USDC • 2 total findings • Cantina • 0xTheBlackPanther

#51

high

Finding not yet public.

medium

Finding not yet public.

circuit-puzzles

circuit-puzzles

1,125.11 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#10

medium

Finding not yet public.

mystic-monorepo

mystic-monorepo

29.31 USDC • 6 total findings • Cantina • 0xTheBlackPanther

#59

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

alchemix-v3

alchemix-v3

95.4 USDC • 5 total findings • Cantina • 0xTheBlackPanther

#57

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

mighty-contracts

mighty-contracts

468.02 USDC • 9 total findings • Cantina • 0xTheBlackPanther

#20

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

mezo-monorepo

mezo-monorepo

226.99 USDC • 4 total findings • Cantina • 0xTheBlackPanther

#33

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Feb '25

defi-app-contracts

defi-app-contracts

11.53 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#26

high

Finding not yet public.

Core Contracts

Core Contracts

93.59 usdc • 5 total findings • CodeHawks • 0xtheblackpanther

#150

medium

Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations

medium

Pending fee not cleared and overwritten by updates via updateFeeType()

medium

closeLiquidation within LendingPool does not allow partial repayments, which can cause massive losses to users within edge case

low

Overwriting Previous Allocations in allocateFunds May Lead to Loss of Cumulative Allocation Data

low

Lack of incentives for users to call LendingPool::initiateLiquidation allows extensive delay between when health factor dropped below threshold and when grace period starts

Jan '25

dahlia-protocol

dahlia-protocol

2,471.89 USDC • 4 total findings • Cantina • 0xTheBlackPanther

#9

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

infrared-contracts

infrared-contracts

100.79 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#50

medium

Finding not yet public.

ton-pool-contracts

ton-pool-contracts

1,124.91 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#7

high

Finding not yet public.

reserve-index-dtf

reserve-index-dtf

53.43 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#8

medium

Finding not yet public.

farcasterattestation-monorepo

farcasterattestation-monorepo

1,176.19 OP • 2 total findings • Cantina • 0xTheBlackPanther

#17

medium

Finding not yet public.

medium

Finding not yet public.

Dec '24

QuantAMM

QuantAMM

45.89 op • 2 total findings • CodeHawks • 0xtheblackpanther

#62

medium

quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.

low

missing implementation for a function to change upliftFee

juicebox-monorepo

juicebox-monorepo

2,962.18 OP • 2 total findings • Cantina • 0xTheBlackPanther

bronze

medium

Finding not yet public.

medium

Finding not yet public.

bima-money

bima-money

5,626.7 USDC • 4 total findings • Cantina • 0xTheBlackPanther

#8

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Oct '24

Dria

Dria

6.56 USDC • 1 total finding • CodeHawks • 0xtheblackpanther

#63

medium

Unrestricted validation score range for validators in `LLMOracleCoordinator::validate`.

Flow

Flow

172.56 USDC • 1 total finding • CodeHawks • 0xtheblackpanther

#8

low

`SablierFlowBase` Lacks `EIP-165` Compliance for `EIP4906` Interface Support

tensor-monorepo

tensor-monorepo

13,384.72 USDC • 3 total findings • Cantina • 0xTheBlackPanther

bronze

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

stakeup-bloomv2

stakeup-bloomv2

511.29 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#22

medium

Finding not yet public.

Sep '24

Liquid Staking

Liquid Staking

505.95 USDC • 3 total findings • CodeHawks • 0xtheblackpanther

#20

high

No LSTs transfer on node operator withdrawals resulting in stuck funds and loss for node operators

low

Oversight while Updating the basis fee in staking pool without updating rewards strategy

low

No way to update unbonding and claim periods

redstone-oracle

redstone-oracle

3,663.52 USDC • 2 total findings • Cantina • 0xTheBlackPanther

#6

high

Finding not yet public.

medium

Finding not yet public.

Aug '24

Centrifuge

Centrifuge

338.49 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#13

medium

Finding not yet public.

zetachain-protocol

zetachain-protocol

90.42 USDC • 2 total findings • Cantina • 0xTheBlackPanther

#69

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

ArkProject: NFT Bridge

ArkProject: NFT Bridge

488.96 USDC • 4 total findings • CodeHawks • 0xtheblackpanther

#20

high

`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`

medium

There is No `msg.value` check in `depositTokens`, causing potential token stuck

medium

Potential Blockage of User Withdrawals When Bridge is Disabled in `withdrawTokens`

low

_disableInitializers is missing in Bridge’s constructor

Biconomy: Nexus

Biconomy: Nexus

237.33 USDC • 2 total findings • CodeHawks • 0xtheblackpanther

#12

medium

Factory deployments won't work correctly on the ZKsync chain

medium

Protocol not fully compliant with `EIP-7579`

May '24

YOLO Games

YOLO Games

679.97 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#6

medium

Finding not yet public.

Apr '24

Beanstalk Part 2

Beanstalk Part 2

748.76 USDC • 1 total finding • CodeHawks • 0xtheblackpanther

#7

medium

```LibWstethEthOracle::getWstethEthPrice``` returns wrong ```wstETH/ETH``` price in some conditions impacting system operations

Mar '24

VenusProtocol/governance-contracts

VenusProtocol/governance-contracts

1,250 USDC • Cantina • 0xTheBlackPanther

#5

Feb '24

Beanstalk Part 1

Beanstalk Part 1

815.35 USDC • 1 total finding • CodeHawks • 0xtheblackpanther

#9

low

LibEthUsdOracle returning wrong price on `minAnswer`, impacting fertilizer minting

arcadexyz/arcade-protocol

arcadexyz/arcade-protocol

16,533.17 USDC • 1 total finding • Cantina • 0xTheBlackPanther

silver

medium

Finding not yet public.

opal-contracts

opal-contracts

1,058.4 USDC • 7 total findings • Cantina • 0xTheBlackPanther

#12

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jan '24

MorpheusAI

MorpheusAI

77.19 USDC • 3 total findings • CodeHawks • 0xtheblackpanther

#16

low

Use custom gas in `sendMintMessage` instead of default gas

low

Create Pool in Mock Distribution is missing validations; allowing duplicates, wrong decreaseInterval value and payoutStart value

low

The `editPool()` lacks a sanity check on the `payoutStart` parameter leading to incorrect or unfair reward distributions

incentive-contracts

incentive-contracts

1,271.97 USDC • 1 total finding • Cantina • 0xTheBlackPanther

#15

medium

Finding not yet public.

Dec '23

stake.link

stake.link

846.43 USDC • 4 total findings • CodeHawks • 0xtheblackpanther

#8

high

A user can steal an already transfered and bridged reSDL lock because of approval

low

SINGLE STEP OWNERSHIP TRANSFER PROCESS

low

Insufficient Gas Limit Specification for Cross-Chain Transfers in _buildCCIPMessage() method. WrappedTokenBridge.sol #210

low

No validation for `_amount` in migrate function