https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/50e1b037-f6a9-442a-aa8c-c91cd9545043.jpg

0xbakeng

Security Researcher

Contact Me

High

10

Total

Medium

9

Total

$6.37K

Total Earnings

#706 All Time

13x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

5x

Top 10

All

Sherlock

Cantina

Immunefi

Jun '25

Superfluid Locker System

Superfluid Locker System

323.57 USDC • 1 total finding • Sherlock • 0xbakeng

#8

high

In `FluidLocker::provideLiquidity` an adversary can bypass the required 1% pump, breaking the intended buy pressure function for all LP providers

May '25

LEND

LEND

113.81 USDC • 3 total findings • Sherlock • 0xbakeng

#29

high

`CoreRouter.sol` allows new borrowers to borrow way more than their collateral should allow them to

high

Adversary can frontrun `_handleValidBorrowRequest()` to redeem or borrow again even though he has already received the borrowed tokens

high

`CoreRouter.sol`’s `repayBorrowInternal` incorrectly updates `same chain` borrow balances on `cross chain` repayments

mystic-monorepo

mystic-monorepo

358.71 USDC • 5 total findings • Cantina • 0xbakeng

#11

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

ZKP2P V2

ZKP2P V2

364.69 OP • Sherlock • 0xbakeng

#6

Findings not publicly available for private contests.

Aegis.im YUSD

Aegis.im YUSD

157.86 OP • 1 total finding • Sherlock • 0xbakeng

bronze

medium

A whale adversary can grief the redeem functionality through redeem limit consumption

Mar '25

Audit Comp | Yeet

Audit Comp | Yeet

37 USDC • 1 total finding • Immunefi • Oxbakeng

#61

low

Finding not yet public.

Feb '25

Rova

Rova

1,178.30 USDC • 2 total findings • Sherlock • 0xbakeng

gold

medium

`Launch.sol::updateParticipation` uses an incorrect variable to check the minimum user token allocation allowed, which can result in an underflow DOS in certain instances

medium

`userTokens` accounting in `Launch.sol::updateParticipation` is updated incorrectly and can lead to loss of user funds, DOS and a broken invariant

Jan '25

dahlia-protocol

dahlia-protocol

1,137.14 USDC • 1 total finding • Cantina • 0xbakeng

#14

medium

Finding not yet public.

Aave v3.3

Aave v3.3

99.67 USDC • Sherlock • 0xbakeng

#79

Dec '24

Tally ARB Staker

Tally ARB Staker

94.32 USDC • Sherlock • 0xbakeng

#23

Audit Comp | Folks: Liquid Staking

Audit Comp | Folks: Liquid Staking

2,264 USDC • 1 total finding • Immunefi • Oxbakeng

#6

high

Finding not yet public.

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

81.25 OP • 4 total findings • Sherlock • 0xbakeng

#26

high

Bad actors can manipulate USDT/USDA exchange rates in `CDS.redeemUSDT()` to redeem an unlimited amount of USDT until Treasury is drained

high

`borrowing.renewOptions()`'s promised 30 days 80% downside protection is not enforced in the `borrowing.liquidate()` or anywhere in the `borrowing.sol`

medium

CDS deposits' `lockingPeriod` is not enforced in CDS.withdraw(), allowing premature exits and creating unfair advantages

medium

Incorrect global borrower count decrement in `BorrowLib.withdraw()` due to local chain validation

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

157.59 USDC • 1 total finding • Sherlock • 0xbakeng

#21

medium

Malicious users can completely evade the slashing in `EthosVouch::slash` by unvouching before `slash` is called, due to the missing 24h lockdown period implementation, resulting in lost slashing fees for Ethos