https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

Boy2000

Security Researcher

High

10

Total

Medium

10

Total

$9.05K

Total Earnings

#577 All Time

9x

Payouts

silver

1x

2nd Places

bronze

1x

3rd Places

regular

5x

Top 10

All

Sherlock

Apr '25

ZKP2P V2

ZKP2P V2

672.40 OP • Sherlock • Boy2000

#5

Findings not publicly available for private contests.

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • Boy2000

#18

medium

Rewards rate can be diluted by attacker

Feb '25

SEDA Protocol

SEDA Protocol

3,084.46 USDC • 8 total findings • Sherlock • Boy2000

#5

high

configDirC not freed

high

Malicious proposer can include empty transactions in a valid proposal

high

Chain halt as VerifyVoteExtensionHandler is not guaranteed to run

high

ASA-2025-003

high

postBatch: inflating votingPower

high

Malicious validator can steal withdraw tokens

medium

requestor can prevent postResult

medium

postRequest can be front run

Rova

Rova

1,178.25 USDC • 1 total finding • Sherlock • Boy2000

silver

medium

updateParticipation confuses CurrencyAmount with TokenAmount

Jan '25

Plaza Finance

Plaza Finance

29.93 USDC • 3 total findings • Sherlock • Boy2000

#59

medium

Auction can be intentionally failed by bidding above poolSaleLimit ratio

medium

Protocol loses portion of accumulated fees after each Auction

medium

Bidders may halt bidding by getting themselves blacklisted

Aave v3.3

Aave v3.3

587.66 USDC • Sherlock • Boy2000

#40

Allora v0.8.0 Update

Allora v0.8.0 Update

2,325.49 USDC • Sherlock • Boy2000

#8

Findings not publicly available for private contests.

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

161.84 OP • 6 total findings • Sherlock • Boy2000

#15

high

execute : target can be any address, including Token. stealing funds

high

Orders created in same block will override each other

high

OracleLess.createOrder passes wrong owner to procureTokens

medium

cancelOrder and adminCancelOrder can be blocked by using blacklisted recipient address. permanent dos

medium

PythOracle.currentValue will return only if price is stale

medium

OracleLess missing maxPendingOrders check, leading to OOG in fillOrder, cancelOrder

Oct '24

Usual V1

Usual V1

1,013.20 USDC • 1 total finding • Sherlock • Boy2000

bronze

high

UsualX.withdraw subtracts from totalDeposits incorrect fee amount