https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/62d37b03-8317-40e7-821d-1dcb23966dec.png

0xleadwizard

Security Researcher

🦀 🦇

Contact Me

High

22

Total

Medium

17

Total

$71.61K

Total Earnings

#137 All Time

17x

Payouts

silver

2x

2nd Places

bronze

2x

3rd Places

regular

6x

Top 10

All

Code4rena

Cantina

CodeHawks

Immunefi

Feb '25

Attackathon | Stacks II

Attackathon | Stacks II

43,047 STX • 1 total finding • Immunefi • leadwiz

#4

high

Finding not yet public.

Jan '25

daao-contracts

daao-contracts

123.83 USDC • 5 total findings • Cantina • 0xleadwizard

#30

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

farcasterattestation-monorepo

farcasterattestation-monorepo

4,695.97 OP • 5 total findings • Cantina • 0xleadwizard

bronze

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Dec '24

aligned-layer

aligned-layer

11,713.12 USDC • 5 total findings • Cantina • 0xleadwizard

silver

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Chainlink Payment Abstraction

Chainlink Payment Abstraction

1,987.07 USDC • Code4rena • 0xleadwizard

bronze
InterPol

InterPol

659.71 USDC • 3 total findings • Cantina • 0xleadwizard

#4

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Lambo.win

Lambo.win

150.47 USDC • 2 total findings • Code4rena • 0xleadwizard

#20

high

Calculation for `directionMask` is incorrect

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

Nov '24

collar-core

collar-core

697.53 USDC • 1 total finding • Cantina • 0xleadwizard

#11

medium

Finding not yet public.

Concrete

Concrete

42.99 USDC • Code4rena • 0xleadwizard

#74

Sep '24

symbioticfi-core

symbioticfi-core

6,511.3 USDC • 2 total findings • Cantina • 0xleadwizard

silver

medium

Finding not yet public.

medium

Finding not yet public.

Aug '24

Fjord Token Staking

Fjord Token Staking

0.19 USDC • 1 total finding • CodeHawks • 0xleadwizard

#20

medium

[H-01] Auction tokens will be lost forever when auction ends without bids

Tadle

Tadle

0.09 USDC • 2 total findings • CodeHawks • 0xleadwizard

#154

high

Native token withdrawal fails until manually approved

medium

Unnecessary balance checks and precision issues in TokenManager::_transfer

Jul '24

Zaros Part 1

Zaros Part 1

125.35 USDC • 4 total findings • CodeHawks • 0xleadwizard

#45

high

Market Disruption and Financial Loss Post-Liquidation

high

`LiquidationBranch::checkLiquidatableAccounts()` executes `for` loop with wrong values, causing array out of bounds to be recovered, the program will not work as expected

medium

An Uninitialized Variable In The `MarketConfiguration::update` Function Causes The `PrepMarket::getIndexPrice` Function To Revert

low

Potential `EIP712` violation in multiple cases

May '24

Munchables

Munchables

0.02 USDC • 2 total findings • Code4rena • 0xleadwizard

#15

high

Invalid validation allows users to unlock early

medium

Missing disapproval check in `LockManager.sol::approveUSDPrice` allows simultaneous approval and disapproval of a price proposal

safe-extensions

safe-extensions

87.5 USDC • 1 total finding • Cantina • 0xleadwizard

#26

medium

Finding not yet public.

Apr '24

DYAD

DYAD

264.19 USDC • 5 total findings • Code4rena • 0xleadwizard

#44

high

Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine

high

Attacker Can Frontruns User's Withdrawals To Make Them Reverts Without Costs

medium

No incentive to liquidate small positions could result in protocol going underwater

medium

Incorrect deployment / missing contract will break functionality

medium

No incentive to liquidate when CR <= 1 as asset received < dyad burned

Mar '24

Taiko

Taiko

1,503.18 USDC • 1 total finding • Code4rena • 0xleadwizard

#14

high

Signatures can be replayed in `withdraw()` to withdraw more tokens than the user originally intended.