https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/ecf338f5-485f-43c0-9460-aec2c132b665.jpg

CoheeYang

Security Researcher

Contact Me

High

4

Total

Medium

6

Total

$1.26K

Total Earnings

#1230 All Time

6x

Payouts

regular

4x

Top 25

regular

4x

Top 50

All

Sherlock

Code4rena

Cantina

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

254.22 USDC • 3 total findings • Sherlock • CoheeYang

#23

high

Unchecked `payload` sent to `GatewayCrossChain` or `GatewayTransferNative` can lead to a loss of valuable tokens.

medium

`GatewaySend::depositAndCall()` will revert with USDT permanetly.

medium

`GatewayTransferNative.sol::onCall()` did not substract `platformFeesForTx` when`decoded.targetZRC20 != zrc20`

May '25

stability-contracts

stability-contracts

150.01 USDC • 1 total finding • Cantina • CoheeYang

#20

medium

Finding not yet public.

mystic-monorepo

mystic-monorepo

42.79 USDC • 2 total findings • Cantina • CoheeYang

#52

high

Finding not yet public.

medium

Finding not yet public.

Apr '25

Kinetiq

Kinetiq

349.77 USDC • 1 total finding • Code4rena • CoheeYang

#18

medium

Attacker can partially DoS L1 operations in StakingManager by making huge number of deposits

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

458.74 USDC • 1 total finding • Code4rena • CoheeYang

#13

high

Early 72-digit adjustment in sqrt will lead to incorrect result exponent calculation

Feb '25

Virtuals Protocol

Virtuals Protocol

9.46 USDC • 2 total findings • Code4rena • CoheeYang

#67

high

Lack of Access Control in `AgentNftV2::addValidator()` Enables Unauthorized Validator Injection and Causes Reward Accounting Inconsistencies

medium

Missing Slippage Protection On Buy And Sell