https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/3dd7b42a-1980-4a02-8285-833919460b42.jpg

0xnija

Security Researcher

Contact Me

High

13

Total

Medium

18

Total

$10.30K

Total Earnings

#632 All Time

14x

Payouts

regular

6x

Top 10

regular

12x

Top 25

regular

13x

Top 50

All

Sherlock

Code4rena

Cantina

Nov '25

Megapot

Megapot

0.13 USDC • 2 total findings • Code4rena • 0xnija

#25

medium

Global Variable Manipulation During Active Draw Alters End Result

medium

Incorrect ticket price reference in JackpotBridgeManager causes user overpayment after price updates

Oct '25

Reflector V3

Reflector V3

198.29 USDC • 4 total findings • Code4rena • 0xnija

#7

high

`set_invocation_costs_config()` fails to authorize admin allowing anyone to set invocation costs

medium

Systematic Overcharge in prices and x_prices: Fee Charged for Requested Records While Return is Capped at 20

medium

Expiration vector length mismatch causes panic in extend_ttl() when assets are added with zero initial expiration period

medium

`twap()` under-charges for multi-period queries due to hardcoded `periods=1`

Index Fun Order Book

Index Fun Order Book

70.67 USDC • 1 total finding • Sherlock • 0xnija

#10

medium

Emergency resolution resolves active epoch, enabling mid-epoch claims and exploitation

Sequence

Sequence

1,622.61 USDC • 2 total findings • Code4rena • 0xnija

#5

medium

`BaseAuth.recoverSapientSignature` returns a constant instead of signer image hash, breaking sapient signer flows

medium

Static signatures bound to caller revert under ERC-4337, causing DoS

Hybra Finance

Hybra Finance

2.31 USDC • 1 total finding • Code4rena • 0xnija

#31

high

Assets deposited before calculating shares amount to mint will cause users to mint less shares.

Sep '25

Ammplify

Ammplify

377.46 USDC • 7 total findings • Sherlock • 0xnija

#16

high

Malicious pool address allows complete drainage of Diamond contract funds

high

Protocol will under-credit compounding maker fees to liquidity providers

high

Protocol users will experience unintended liquidity operations on neighboring positions

medium

Unfair principal slashing when burning via NFT (JIT penalty mis-trigger)

medium

NFT mints block after 16 assets due to NFTManager ownership

medium

Sole compounding makers will have funds permanently locked when attempting full withdrawal

medium

Timed ownership transfer mechanism permanently blocks governance operations

Aug '25

kuru-contracts

kuru-contracts

313.61 USDC • 1 total finding • Cantina • 0xnija

#54

high

Finding not yet public.

GTE Perps and Launchpad

GTE Perps and Launchpad

1,376.89 USDC • 3 total findings • Code4rena • 0xnija

#15

high

`GTELaunchpadV2Pair::burn` over-estimates distribution amounts when there are non-zero accrued launchpad fees

high

Total reward shares for token can reach zero after unlocking, causing `GTELaunchpadV2Pair` to be bricked

medium

`LaunchToken` transfers cause staking rewards to be lost to the `LaunchPad`

Clementine

Clementine

3,063.82 USDC • 1 total finding • Cantina • 0xnija

#4

high

Finding not yet public.

Jul '25

succinct-network

succinct-network

308.26 USDC • 2 total findings • Cantina • 0xnija

#18

medium

Finding not yet public.

medium

Finding not yet public.

genius-contracts

genius-contracts

1,395.81 USDC • 3 total findings • Cantina • 0xnija

#5

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jun '25

solaxy

solaxy

316.85 USDC • 1 total finding • Cantina • 0xnija

#13

high

Finding not yet public.

May '25

ammalgam-contracts

ammalgam-contracts

114.56 USDC • 1 total finding • Cantina • 0xnija

#18

high

Finding not yet public.

circuit-puzzles

circuit-puzzles

1,139.23 USDC • 2 total findings • Cantina • 0xnija

#8

high

Finding not yet public.

medium

Finding not yet public.