https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

Goran

Security Researcher

Contact Me

High

4

Total

Medium

10

Total

$1.54K

Total Earnings

#1170 All Time

3x

Payouts

regular

2x

Top 25

regular

3x

Top 50

All

Sherlock

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

458.74 USDC • 8 total findings • Sherlock • Goran

#15

high

Anyone can steal refunds intended for Solana receivers

high

GatewayTransferNative can be drained via ETH_ADDRESS token collection bypass

medium

Cross-chain swaps will fail for USDT

medium

On-chain slippage calculation can cause user to lose all funds

medium

ETH refunds are always lost due to incorrect transfer logic in onRevert

medium

Bitcoin refunds in onRevert are sent to uncontrolled EVM Addresses and permanently lost

medium

Bug in AccountEncoder causes wrong Solana account permissions

medium

GatewayTransferNative does not collect platform fee when native asset is bridged

Apr '25

ZetaChain Cross-Chain

ZetaChain Cross-Chain

1,023.61 USDC • 2 total findings • Sherlock • Goran

#11

medium

Cross-chain calls from Solana are enabled even when gateway is paused

medium

Abort processing after call originating from Solana will cause loss of funds

Jan '25

Plaza Finance

Plaza Finance

55.11 USDC • 4 total findings • Sherlock • Goran

#46

high

Invalid index used to fetch auction's address will prevent any auction from successfully ending

high

Fee beneficiary can miss collecting the fees due to the broken calculation

medium

Underflow in collateral calculation can cause inability to redeem

medium

Attacker can drain most of the reserves by weaponizing USDC blacklisting