https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/118e4d04-9aa2-4932-9097-31875880c37d.jpg

0xmujahid002

Security Researcher

Security Researcher with Solidity Skill: Over-Thinkinggg!

Contact Me

High

4

Total

Medium

5

Total

$213.00

Total Earnings

#1653 All Time

11x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

2x

Top 10

All

Sherlock

Code4rena

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

2.71 USDC • Sherlock • 0xmujahid002

#71

Feb '25

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • 0xmujahid002

bronze

medium

A participant can bypass token limits and misallocate tokens due to incorrect arithmetic in `updateParticipation`

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • 0xmujahid002

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

IQ AI

IQ AI

3.58 USDC • 1 total finding • Code4rena • 0xmujahid002

#16

medium

Ineffective proposal threshold validation allows setting arbitrary high values

Aave v3.3

Aave v3.3

32.55 USDC • Sherlock • 0xmujahid002

#96

Dec '24

Tally ARB Staker

Tally ARB Staker

43.63 USDC • Sherlock • 0xmujahid002

#28

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

23.45 OP • 2 total findings • Sherlock • 0xmujahid002

#28

high

Failure to Reset Token Allowances Exposes Contracts to Token Draining Risk

medium

Incorrect logic allows stale prices to pass validation

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

0.14 OP • 1 total finding • Sherlock • 0xmujahid002

#67

high

A malicious actor can arbitrarily modify the `downsideProtected` value, affecting the CDS system’s calculations.

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

0.38 USDC • 1 total finding • Sherlock • 0xmujahid002

#33

high

An attacker can understate `marketFunds` by selling votes, leading to unauthorized withdrawal.

vVv Launchpad - Investments & Token distribution

vVv Launchpad - Investments & Token distribution

94.59 USDC • 1 total finding • Sherlock • 0xmujahid002

gold

high

Attackers Can Claim Funds Meant for KYC-Verified Users by Exploiting Missing `msg.sender` Verification

Debita Finance V3

Debita Finance V3

12.57 USDC • 1 total finding • Sherlock • 0xmujahid002

#49

medium

Miscalculation of `extendedTime` During Loan Extension