https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

0xnegan

Security Researcher

Contact Me

High

6

Total

Medium

15

Total

$662.00

Total Earnings

#1352 All Time

22x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

6x

Top 10

All

Sherlock

Code4rena

CodeHawks

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

2.69 USDC • 1 total finding • Code4rena • Shinobi

#29

high

Natural Logarithm Function Silently Accepts Invalid Non-Positive Inputs

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

0.03 USDC • Sherlock • yuza101

#94

Symmio, Staking and Vesting

Symmio, Staking and Vesting

68.35 USDC • 1 total finding • Sherlock • 0xCNX

#11

high

Precision Loss in Reward Calculations Undermines User Rewards

Feb '25

Yieldoor

Yieldoor

0.09 USDC • 1 total finding • Sherlock • 0xnegan

#28

medium

Locked funds due to underflow in withdrawal

Yieldoor

Yieldoor

0.09 USDC • 1 total finding • Sherlock • yuza101

#28

medium

[m-01] Withdraw Calculation Bug

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • 0xnegan

bronze

medium

[LP-01] Unit Mismatch in Participation Updates to over/under charging during participation updates

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • yuza101

bronze

medium

Critical Logic Mismatch in updateParticipation() Leads to Guaranteed Reverts or Corrupted Token Allocations

Liquidity Management

Liquidity Management

193.43 usdc • 3 total findings • CodeHawks • cipherhawk

#24

high

Wrong refundExecutionFee in _handleReturn

medium

Wrong index causes last depositor to always get execution fee refund if cancelFlow is called by keeper to cancel a withdrawal

low

PerpetualVault withdrawals are affected by global parameter updates

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • Shinobi

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

IQ AI

IQ AI

3.58 USDC • 1 total finding • Code4rena • Shinobi

#16

medium

Ineffective proposal threshold validation allows setting arbitrary high values

Aave DIVA Wrapper

Aave DIVA Wrapper

0.04 usdc • 1 total finding • CodeHawks • cipherhawk

#9

low

Incorrect sequence of AaveDIVAWrapper constructor parameters

Aave v3.3

Aave v3.3

57.84 USDC • Sherlock • 0xnegan

#90

Aave v3.3

Aave v3.3

0.29 USDC • Sherlock • 0xCNX

#119

Dec '24

Ethos Reputation Market Fix Review Contest

Ethos Reputation Market Fix Review Contest

144.76 USDC • 1 total finding • Sherlock • 0xnegan

silver

medium

Rounding Arbitrage (Different Rounding for Trust vs. Distrust)

Alchemix Transmuter

Alchemix Transmuter

11.67 op • 2 total findings • CodeHawks • cipherhawk

#26

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

low

Old router retains token allowance after update

Flex Perpetuals

Flex Perpetuals

62.48 USDC • 1 total finding • Code4rena • Shinobi

#4

medium

Missing slippage protection in `AerodromeDexter.sol` `swapExactTokensForTokens()`

SecondSwap

SecondSwap

5.11 USDC • 3 total findings • Code4rena • Shinobi

#49

high

Users can claim more that their actual allotment

medium

Creator of one vesting plan can affect vesting plans created by other users.

medium

Listing potential can not be purchased with discounted price

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

0.14 OP • 1 total finding • Sherlock • 0xnegan

#67

high

updateDownsideProtected() to Deny Service and Cause Protocol Disruption

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

0.26 OP • 1 total finding • Sherlock • yuza101

#63

medium

[M-03] No limit to how many orders can be pushed into pendingOrderIds[], potentially lead to DoS

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

0.01 OP • 1 total finding • Sherlock • 0xCNX

#65

medium

Incorrect Freshness Logic Validation in PythOracle breaking the entire mechanism for triggering orders

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

0.14 OP • 1 total finding • Sherlock • 0xCNX

#67

high

Attacker will Deny Service by Manipulating downsideProtected in updateDownsideProtected()

Oct '24

AXION

AXION

111.80 USDC • 1 total finding • Sherlock • yuza101

#10

medium

Potential Integer Division Precision Loss in boostPrice Function Leads to Inaccurate Price Calculations