https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/32413a01-dabf-4235-8c9e-9cfe6b7f8c78.png

Aamirusmani1552

Security Researcher

Independent Security Researcher

Contact Me

High

44

Total

Medium

26

Total

$92.83K

Total Earnings

#118 All Time

35x

Payouts

gold

3x

1st Places

bronze

3x

3rd Places

regular

18x

Top 10

All

Sherlock

Code4rena

Cantina

Jan '26

Hotstuff

Hotstuff

15.82 USDC • Sherlock • Aamirusmani1552

#53

Findings not publicly available for private contests.

Nov '25

SukukFi

SukukFi

0 USDC • 2 total findings • Code4rena • Aamir

#20

high

Finding not yet public.

medium

Finding not yet public.

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

269.12 OP • 5 total findings • Sherlock • Aamirusmani1552

#6

high

`TokenRewardInfo::lastRewardIndex` is also updated in the `SuperDCAStaking::stake(...)` along with the global index without minting the rewards for that period.

high

Protocol does not support ETH as a pool token

high

`SuperDCAGuage` can be used in the different pool to steal the rewards of the listed NFP's pool

medium

`SuperDCACashback` does not support USDC with different decimals than 6

medium

New mint rate is set in the `SuperDCAStaking` without updating the global `rewardIndex`

May '25

stability-contracts

stability-contracts

77.49 USDC • 1 total finding • Cantina • Aamirusmani1552

#26

high

Finding not yet public.

superform-core

superform-core

2,350.5 USDC • 4 total findings • Cantina • Aamirusmani1552

#8

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

Burve

Burve

1,193.15 USDC • 1 total finding • Sherlock • Aamirusmani1552

#13

high

Fee accrued can be stolen by new LPs if fee is collected in one token only or collected in large amount for the other token.

Mar '25

eigenlayer-contracts

eigenlayer-contracts

68,668.11 USDC • 1 total finding • Cantina • Aamirusmani1552

bronze

medium

Finding not yet public.

Feb '25

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • Aamirusmani1552

bronze

medium

Incorrect check in `Launch::updateParticipation(...)` for min and max token amounts

Jan '25

Liquid Ron

Liquid Ron

4,490.59 USDC • 3 total findings • Code4rena • Aamir

gold

high

The calculation of `totalAssets()` could be wrong if `operatorFeeAmount` > 0, this can cause potential loss for the new depositors

medium

User can earn rewards by frontrunning the new rewards accumulation in Ron staking without actually delegating his tokens

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

daao-contracts

daao-contracts

575.23 USDC • 9 total findings • Cantina • Aamirusmani1552

gold

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

doppler-contracts

doppler-contracts

4,571.2 USDC • 3 total findings • Cantina • Aamirusmani1552

#6

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

hmx-orderbook

hmx-orderbook

1,931.42 USDC • 2 total findings • Cantina • Aamirusmani1552

#4

medium

Finding not yet public.

medium

Finding not yet public.

Nov '24

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

123.11 USDC • Sherlock • Aamirusmani1552

#26

vVv Launchpad - Investments & Token distribution

vVv Launchpad - Investments & Token distribution

94.59 USDC • 1 total finding • Sherlock • Aamirusmani1552

gold

high

Incorrect Parameter in `safeTransferFrom(...)` May Result in Theft of User's Claim Amount

Telcoin Update #2

Telcoin Update #2

71.84 USDC • Sherlock • Aamirusmani1552

#21

Aug '24

zetachain-protocol

zetachain-protocol

778.51 USDC • 5 total findings • Cantina • Aamirusmani1552

#25

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

Reserve Core

Reserve Core

0 USDC • Code4rena • Aamir

#7

MakerDAO Endgame

MakerDAO Endgame

435.17 USDC • Sherlock • Aamirusmani1552

#75

May '24

safe-extensions

safe-extensions

2,414.66 USDC • 2 total findings • Cantina • Aamirusmani1552

#10

medium

Finding not yet public.

medium

Finding not yet public.

Apr '24

Renzo

Renzo

0.04 USDC • 2 total findings • Code4rena • Aamir

#57

high

Incorrect withdraw queue balance in TVL calculation

medium

Deposits will always revert if the amount being deposited is less than the bufferToFill value

DYAD

DYAD

52.4 USDC • 6 total findings • Code4rena • Aamir

#67

high

Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine

high

Kerosene collateral is not being moved on liquidation, exposing liquidators to loss

high

User can get their Kerosene stuck because of an invalid check on withdraw

high

Unable to withdraw Kerosene from `vaultmanagerv2::withdraw` as it expects a `vault.oracle()` method which is missing in Kerosene vaults

medium

No incentive to liquidate small positions could result in protocol going underwater

medium

Incorrect deployment / missing contract will break functionality

Mar '24

Ondo Finance

Ondo Finance

8.28 USDC • Code4rena • Aamir

#17

RadicalxChange

RadicalxChange

1.18 USDC • 1 total finding • Sherlock • Aamirusmani1552

bronze

high

The highest bidder can cancel all of his bids and claim the Steward License for free

WOOFi Swap

WOOFi Swap

127.48 USDC • 1 total finding • Sherlock • Aamirusmani1552

#9

medium

Loss of Tokens Due to Incorrect Fee Deduction in `WooCrossChainRouterV4`

Feb '24

UniStaker Infrastructure

UniStaker Infrastructure

716.32 USDC • Code4rena • Aamir

#4

AI Arena

AI Arena

112.92 USDC • 6 total findings • Code4rena • Aamir

#54

high

Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Since you can reroll with a different fighterType than the NFT you own, you can reroll bypassing maxRerollsAllowed and reroll attributes based on a different fighterType

high

Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes

high

Fighters cannot be minted after the initial generation due to uninitialized `numElements` mapping

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

Jan '24

Decent

Decent

885.14 USDC • 3 total findings • Code4rena • Aamir

#10

high

When `DecentBridgeExecutor.execute` fails, funds will be sent to a random address

high

Users will lose their cross-chain transaction if the destination router do not have enough WETH reserves.

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

Telcoin Platform Audit

Telcoin Platform Audit

1,227.22 USDC • 3 total findings • Sherlock • Aamirusmani1552

#5

high

`StakingRewardsManager::topUp(...)` Misallocates Funds to `StakingRewards` Contracts

high

`CouncilMember::burn()` does not update states correctly leading to the loss of tokens to the council members.

medium

Sablier stream update in `CouncilMember.sol` can cause loss of funds if the streamed balance is not withdrawn.

Dec '23

Footium Update

Footium Update

3.94 USDC • Sherlock • Aamirusmani1552

#33

Revolution Protocol

Revolution Protocol

207.58 USDC • 2 total findings • Code4rena • Aamir

#30

medium

CultureIndex.sol#dropTopVotedPiece() - Malicious user can manipulate topVotedPiece to DoS the whole CultureIndex and AuctionHouse

medium

`encodedData` argument of `hashStruct` is not calculated perfectly for EIP712 singed messages in `CultureIndex.sol`

Nov '23

Nouns Builder

Nouns Builder

21.94 USDC • 1 total finding • Sherlock • Aamirusmani1552

#9

high

Founders will not be able to mint their token share if their assigned token ID is in the hundreds (i.e., 100, 200).

Kelp DAO | rsETH

Kelp DAO | rsETH

946.02 USDC • 3 total findings • Code4rena • Aamir

#9

high

The price of rsEHT could be manipulated by the first staker

high

Possible arbitrage from Chainlink price discrepancy

high

Protocol mints less rsETH on deposit than intended

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

29.29 USDC • 1 total finding • Code4rena • Aamir

#51

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

Allo V2

Allo V2

0.09 USDC • 1 total finding • Sherlock • Aamirusmani1552

#74

medium

Fee-on-transfer tokens aren't supported

Aug '23

Chainlink Staking v0.2

Chainlink Staking v0.2

427.49 USDC • Code4rena • Aamir

#42