https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/50e1b037-f6a9-442a-aa8c-c91cd9545043.jpg

0xbakeng

Security Researcher

Contact Me

High

3

Total

Medium

7

Total

$5.57K

Total Earnings

#716 All Time

10x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

4x

Top 10

All

Sherlock

Cantina

Immunefi

Apr '25

ZKP2P V2

ZKP2P V2

364.69 OP • Sherlock • 0xbakeng

#6

Findings not publicly available for private contests.

Aegis.im YUSD

Aegis.im YUSD

157.86 OP • 1 total finding • Sherlock • 0xbakeng

bronze

medium

A whale adversary can grief the redeem functionality through redeem limit consumption

Mar '25

Audit Comp | Yeet

Audit Comp | Yeet

37 USDC • 1 total finding • Immunefi • Oxbakeng

#61

low

Finding not yet public.

Feb '25

Rova

Rova

1,178.30 USDC • 2 total findings • Sherlock • 0xbakeng

gold

medium

`Launch.sol::updateParticipation` uses an incorrect variable to check the minimum user token allocation allowed, which can result in an underflow DOS in certain instances

medium

`userTokens` accounting in `Launch.sol::updateParticipation` is updated incorrectly and can lead to loss of user funds, DOS and a broken invariant

Jan '25

dahlia-protocol

dahlia-protocol

1,137.14 USDC • 1 total finding • Cantina • 0xbakeng

#14

medium

Finding not yet public.

Aave v3.3

Aave v3.3

99.67 USDC • Sherlock • 0xbakeng

#79

Dec '24

Tally ARB Staker

Tally ARB Staker

94.32 USDC • Sherlock • 0xbakeng

#23

Audit Comp | Folks: Liquid Staking

Audit Comp | Folks: Liquid Staking

2,264 USDC • 1 total finding • Immunefi • Oxbakeng

#6

high

Finding not yet public.

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

81.25 OP • 4 total findings • Sherlock • 0xbakeng

#26

high

Bad actors can manipulate USDT/USDA exchange rates in `CDS.redeemUSDT()` to redeem an unlimited amount of USDT until Treasury is drained

high

`borrowing.renewOptions()`'s promised 30 days 80% downside protection is not enforced in the `borrowing.liquidate()` or anywhere in the `borrowing.sol`

medium

CDS deposits' `lockingPeriod` is not enforced in CDS.withdraw(), allowing premature exits and creating unfair advantages

medium

Incorrect global borrower count decrement in `BorrowLib.withdraw()` due to local chain validation

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

157.59 USDC • 1 total finding • Sherlock • 0xbakeng

#21

medium

Malicious users can completely evade the slashing in `EthosVouch::slash` by unvouching before `slash` is called, due to the missing 24h lockdown period implementation, resulting in lost slashing fees for Ethos