https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/24ab0440-ea46-4cbd-8cff-bf1565d272a1.jpg

Edoscoba

Security Researcher

Blockchain Security Researcher

Contact Me

High

9

Total

Medium

23

Total

$4.43K

Total Earnings

#926 All Time

17x

Payouts

regular

2x

Top 10

regular

9x

Top 25

regular

13x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

Dec '25

Monolith Stablecoin Factory

Monolith Stablecoin Factory

164.34 USDC • 4 total findings • Sherlock • Edoscoba

#11

medium

Permanent Interest Freeze via Exponential Decay Domain Violation

medium

Undercharging Interest When Borrow Rate Decays to MIN_RATE

medium

Redemptions Can Create a Collateral Deficit When a Free-Debt Borrower Is Underwater

medium

`writeOff()` Can Zero Total Debt When the Written-Off Account Is the Last Borrower

Nov '25

Megapot

Megapot

102.84 USDC • 2 total findings • Code4rena • edoscoba

#18

medium

Changing Entropy Provider During Active Drawing Causes Permanent Protocol Lock and Callback Failure

medium

Changing Payout Calculator During Active Drawing Causes Loss of Unclaimed Winnings

Oct '25

Reflector V3

Reflector V3

0.33 USDC • 3 total findings • Code4rena • edoscoba

#14

high

`set_invocation_costs_config()` fails to authorize admin allowing anyone to set invocation costs

medium

`twap()` under-charges for multi-period queries due to hardcoded `periods=1`

medium

Systematic Overcharge in prices and x_prices: Fee Charged for Requested Records While Return is Capped at 20

Index Fun Order Book

Index Fun Order Book

70.67 USDC • 1 total finding • Sherlock • Edoscoba

#10

medium

Over‑Permissive Readiness in Continuous/Manual Markets Enables Premature Resolution

Sep '25

Ammplify

Ammplify

258.84 USDC • 3 total findings • Sherlock • Edoscoba

#29

medium

adjustMaker ignores recipient parameter, always settles to msg.sender

medium

MakerFacet: collectFees resets JIT penalty age for non-compounding positions

medium

Incorrect rootWidth computation in Tick.sol causes index underflow/wrap and tree corruption

Aug '25

kuru-contracts

kuru-contracts

919 USDC • 2 total findings • Cantina • edoscoba

#26

high

Finding not yet public.

high

Finding not yet public.

Jul '25

GTE Spot CLOB and Router

GTE Spot CLOB and Router

3.44 USDC • 1 total finding • Code4rena • edoscoba

#23

medium

FOK orders wrongly revert on dust residual amounts below lot size

May '25

circuit-puzzles

circuit-puzzles

450.07 USDC • 1 total finding • Cantina • edoscoba

#13

medium

Finding not yet public.

mystic-monorepo

mystic-monorepo

88.19 USDC • 4 total findings • Cantina • edoscoba

#33

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

alchemix-v3

alchemix-v3

74.57 USDC • 3 total findings • Cantina • edoscoba

#66

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

Cabal Liquid Staking Token

Cabal Liquid Staking Token

2,116.67 USDC • 1 total finding • Code4rena • edoscoba

#4

medium

LP Redelegation Uses Inaccurate Internal Tracker Amount, Leading to Potential Failures or Orphaned Funds

mezo-monorepo

mezo-monorepo

158.82 USDC • 2 total findings • Cantina • edoscoba

#35

medium

Finding not yet public.

medium

Finding not yet public.

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

0.00 USDC • Sherlock • Edoscoba

#110

Crestal Network

Crestal Network

0.01 USDC • 1 total finding • Sherlock • Edoscoba

#12

high

Critical Unauthorized ERC20 Token Draining Vulnerability in Payment Contract's payWithERC20 Function

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • Edoscoba

#18

medium

An attacker will dilute rewards for legitimate stakers

Feb '25

Virtuals Protocol

Virtuals Protocol

21.27 USDC • 1 total finding • Code4rena • edoscoba

#64

medium

[H-1] Missing totalSupply Reduction in burnFrom Allows Supply Manipulation (ERC20 Violation)

Core Contracts

Core Contracts

0.58 usdc • 2 total findings • CodeHawks • edoscoba

#360

high

RAACNFT mint function receives funds to address(this) but has no way of withdrawing them

medium

Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations