https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/5b2f1940-36f1-41ae-8ccd-bc5ea638e773.png

Atharv

Security Researcher

Working as a Blockchain Developer at @blocktheoryhq | A technology enthusiast with a passion for learning Web3 | 👥 Member @developer_dao

Contact Me

High

19

Total

Medium

16

Total

$8.41K

Total Earnings

#601 All Time

19x

Payouts

gold

2x

1st Places

silver

1x

2nd Places

bronze

2x

3rd Places

All

Sherlock

Code4rena

Cantina

CodeHawks

Apr '25

Pareto USP, a credit-backed synthetic dollar

Pareto USP, a credit-backed synthetic dollar

2,166.66 USDC • 1 total finding • Sherlock • Atharv

gold

medium

Asymmetric Loss Distribution: Non-stakers Penalized by First-To-Withdraw Advantage After Yield Farming Losses

Feb '25

Liquidity Management

Liquidity Management

43.87 usdc • 1 total finding • CodeHawks • atharv181

#45

high

Deposits on long one leverage vault don't actually finalize the flow, leading to a Denial of Service (DoS)

Jan '25

IQ AI

IQ AI

243.25 USDC • 1 total finding • Code4rena • Atharv

#13

high

Adversary can win proposals with voting power as low as 4%

Dec '24

QuantAMM

QuantAMM

157.82 op • 6 total findings • CodeHawks • atharv181

#42

high

Out-of-Bounds Array Access in `_calculateQuantAMMVariance` with Odd Number of Assets and Vector Lambda

high

Fee Evasion via LP Token Transfer Resets Deposit Value

high

Owner fee will be locked in `UpliftOnlyExample` contract due to incorrect recipient address in `UpliftOnlyExample::onAfterSwap`

medium

quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.

medium

“Uplift Fee” Incorrectly Falls Back to Minimum Fee Due to Integer Division

medium

Transferring deposit NFT doesn't check if the receiver exceeds the 100 deposit limit

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

1.54 OP • 2 total findings • Sherlock • Atharv

#54

high

Reentrancy Attack in `fillOrder` Function of OracleLess.sol

high

Duplicate Order ID Vulnerability can Drain the Whole Protocol

Nov '24

RuneMine by Mine Labs’

RuneMine by Mine Labs’

2,281.58 USDC • Sherlock • Atharv

#4

Findings not publicly available for private contests.

vVv Launchpad - Investments & Token distribution

vVv Launchpad - Investments & Token distribution

94.59 USDC • 1 total finding • Sherlock • Atharv

gold

high

Frontrunning Vulnerability in claim() Function Leading to Loss of Rewards

Oct '24

Covalent - EWM Light Client

Covalent - EWM Light Client

1,729.02 USDC • Sherlock • Atharv

silver

Findings not publicly available for private contests.

Gamma Brevis Rewarder

Gamma Brevis Rewarder

131.06 OP • 1 total finding • Sherlock • Atharv

bronze

high

Improper Epoch Handling in `handleProofResult()` Function Leading to Unclaimable Rewards

AXION

AXION

50.94 USDC • 1 total finding • Sherlock • Atharv

#12

medium

Protocol is not complient with ERC1504

stakeup-bloomv2

stakeup-bloomv2

32.44 USDC • 3 total findings • Cantina • atharv181

#77

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Sep '24

Boost Core Incentive Protocol

Boost Core Incentive Protocol

507.98 USDC • 5 total findings • Sherlock • Atharv

#7

high

Boost Creator Loses Access to Reclaim Funds Due to Owner Assignment in Deployed Incentive Contracts

medium

Loss of Fee in Boost Protocol Due to Referral Fee Manipulation

medium

Incompatibility with Fee-on-Transfer Tokens Causes Transaction Reverts

medium

Weak Randomness in drawRaffle() Function Allows Manipulation by Block Proposers

medium

Protocol Fails to Handle Rebasing Tokens, Leading to Potential Reward Losses for users

Aug '24

Sentiment V2

Sentiment V2

125.43 USDC • 3 total findings • Sherlock • Atharv

#28

medium

maxDeposit doesn't comply with ERC-4626

medium

User can deposit into the `superpool` even when the pool is paused.

medium

Incorrect Handling of Base Pool Caps in Superpool.sol Could Lead to Suboptimal Fund Distribution.

Tadle

Tadle

5.86 USDC • 6 total findings • CodeHawks • atharv181

#110

high

TokenManager - Unlimited withdraw

high

Native token withdrawal fails until manually approved

high

`DeliveryPlace::settleAskTaker` Has Incorrect Access Control

high

Malicious user can drain protocol by bypassing `ASK` offer abortion validation in `Turbo` mode

medium

Unnecessary balance checks and precision issues in TokenManager::_transfer

low

`listOffer` Unsafely References Fungible Identifiers

Jun '24

Vultisig

Vultisig

6.78 USDC • 1 total finding • Code4rena • Atharv

#31

high

Vultisig whitelisting can be bypassed by anyone

Apr '24

Renzo

Renzo

0 USDC • 1 total finding • Code4rena • Atharv

#58

high

Incorrect withdraw queue balance in TVL calculation

Mar '24

RadicalxChange

RadicalxChange

1.18 USDC • 1 total finding • Sherlock • Atharv

bronze

high

`EnglishPeriodicAuctionInternal.sol:_cancelAllBids` function can cancel the highest bid

Jan '24

Arcadia

Arcadia

760.52 USDC • 1 total finding • Sherlock • Atharv

#7

medium

Dilution of Donations in Tranche

Covalent

Covalent

67.18 USDC • 1 total finding • Sherlock • Atharv

#13

medium

Sandwich Attack on rewardValidators Function, Attacker can earn max-profit quickly.