https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/916ae18a-67d1-401e-b164-4a441aa5207f.png

0xastronatey

Security Researcher

Protocol security engineer building Auron, an autonomous AI security researcher, while also leveraging it to identify vulnerabilities in competitive audits

Contact Me

High

8

Total

Medium

16

Total

$26.06K

Total Earnings

#368 All Time

15x

Payouts

gold

1x

1st Places

bronze

3x

3rd Places

regular

7x

Top 10

All

Sherlock

Code4rena

Mar '26

Chainlink Payment Abstraction V2

Chainlink Payment Abstraction V2

15,714.5 USDC • 3 total findings • Code4rena • 0xastronatey

gold

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Current Finance

Current Finance

184.59 USDC • 2 total findings • Sherlock • 0xastronatey

#15

medium

close_liquidity_mining_rewards can confiscate already-earned rewards from passive pre-existing users

medium

Debt-side ADL checks global reserve debt instead of per-group debt, so one e-mode group can force-liquidate healthy users in another group

Intuition

Intuition

432.59 USDC • 1 total finding • Code4rena • 0xastronatey

bronze

medium

Epoch-boundary checkpoints retroactively qualify for the previous epoch's rewards

Feb '26

Injective Peggy Bridge

Injective Peggy Bridge

34.87 USDC • 3 total findings • Code4rena • 0xastronatey

#18

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jan '26

Olas

Olas

14.37 USDC • 3 total findings • Code4rena • 0xastronatey

#52

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Fluid DEX v2

Fluid DEX v2

194.51 USDC • 2 total findings • Sherlock • 0xastronatey

#10

high

Incorrect clamp in MoneyMarket normal withdraw allows over-withdrawal from Liquidity, leading to direct theft of pooled user funds

medium

Stored-credit IOU is assigned to `to_` but only claimable by `msg.sender`, permanently locking funds on Liquidity failure

Feb '25

THORWallet

THORWallet

0.35 USDC • 2 total findings • Code4rena • 0xastronatey

#7

high

MergeTgt has no handling if TGT_TO_EXCHANGE is exceeded during the exchange period

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Stealth Project by Textile

Stealth Project by Textile

1,469.31 USDC • Code4rena • 0xastronatey

#7

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • 0xastronatey

#11

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

Dec '24

SecondSwap

SecondSwap

1.21 USDC • 3 total findings • Code4rena • 0xastronatey

#60

high

Users can claim more that their actual allotment

medium

Listing potential can not be purchased with discounted price

medium

Incorrect listing type validation bypasses enforcement of minimum purchase amount

Chainlink Payment Abstraction

Chainlink Payment Abstraction

1,987.07 USDC • Code4rena • 0xastronatey

bronze

Sep '24

Kakarot

Kakarot

6,026.65 USDC • 2 total findings • Code4rena • 0xastronatey

bronze

high

Unauthorized Contracts Can Bypass Precompile Authorization via delegatecall in Kakarot zkEVM

high

Three valid signatures for the same message

Aug '24

The Wildcat Protocol

The Wildcat Protocol

0 USDC • Code4rena • 0xastronatey

#12

Chakra

Chakra

0.07 USDT • 1 total finding • Code4rena • 0xastronatey

#63

high

There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` function

Superposition

Superposition

1.26 USDC • 1 total finding • Code4rena • 0xastronatey

#32

medium

_onTransferReceived() does not work as intended