https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

Boy2000

Security Researcher

High

13

Total

Medium

14

Total

$9.20K

Total Earnings

#635 All Time

12x

Payouts

silver

1x

2nd Places

bronze

1x

3rd Places

regular

7x

Top 10

All

Sherlock

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

68.94 OP • 5 total findings • Sherlock • Boy2000

#19

high

Pending rewards are lost on stake/unstake

high

collectFees will revert with eth-dca

high

CashbackClaim.startTime is never used

medium

_convertToUSDCPrecision USDC on BNB has 18 decimals

medium

setMintRate does not update index

Aug '25

Yield Basis

Yield Basis

69.47 USDC • 1 total finding • Sherlock • Boy2000

#10

medium

set_gauge_controller accepts only empty gc

May '25

LayerEdge - Staking

LayerEdge - Staking

7.19 USDC • 1 total finding • Sherlock • Boy2000

#7

medium

Unbound loop in _updateInterest

Apr '25

ZKP2P V2

ZKP2P V2

672.40 OP • Sherlock • Boy2000

#5

Findings not publicly available for private contests.

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • Boy2000

#18

medium

Rewards rate can be diluted by attacker

Feb '25

SEDA Protocol

SEDA Protocol

3,084.46 USDC • 8 total findings • Sherlock • Boy2000

#5

high

configDirC not freed

high

Malicious proposer can include empty transactions in a valid proposal

high

Chain halt as VerifyVoteExtensionHandler is not guaranteed to run

high

ASA-2025-003

high

postBatch: inflating votingPower

high

Malicious validator can steal withdraw tokens

medium

requestor can prevent postResult

medium

postRequest can be front run

Rova

Rova

1,178.25 USDC • 1 total finding • Sherlock • Boy2000

silver

medium

updateParticipation confuses CurrencyAmount with TokenAmount

Jan '25

Plaza Finance

Plaza Finance

29.93 USDC • 3 total findings • Sherlock • Boy2000

#59

medium

Auction can be intentionally failed by bidding above poolSaleLimit ratio

medium

Protocol loses portion of accumulated fees after each Auction

medium

Bidders may halt bidding by getting themselves blacklisted

Aave v3.3

Aave v3.3

587.66 USDC • Sherlock • Boy2000

#40

Allora v0.8.0 Update

Allora v0.8.0 Update

2,325.49 USDC • Sherlock • Boy2000

#8

Findings not publicly available for private contests.

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

161.84 OP • 6 total findings • Sherlock • Boy2000

#15

high

execute : target can be any address, including Token. stealing funds

high

Orders created in same block will override each other

high

OracleLess.createOrder passes wrong owner to procureTokens

medium

cancelOrder and adminCancelOrder can be blocked by using blacklisted recipient address. permanent dos

medium

PythOracle.currentValue will return only if price is stale

medium

OracleLess missing maxPendingOrders check, leading to OOG in fillOrder, cancelOrder

Oct '24

Usual V1

Usual V1

1,013.20 USDC • 1 total finding • Sherlock • Boy2000

bronze

high

UsualX.withdraw subtracts from totalDeposits incorrect fee amount