https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_1.png

HeckerTrieuTien

Security Researcher

High

24

Total

Medium

21

Total

$9.74K

Total Earnings

#613 All Time

21x

Payouts

bronze

1x

3rd Places

regular

7x

Top 10

regular

11x

Top 25

All

Sherlock

Code4rena

Cantina

Sep '25

octant-v2-core

octant-v2-core

2,388.22 USDC • 1 total finding • Cantina • HeckerTrieuTien

#7

high

Finding not yet public.

Ammplify

Ammplify

1,421.73 USDC • 5 total findings • Sherlock • HeckerTrieuTien

#6

high

Any depositor can pay for liquidity but receive zero shares, causing principal loss to the depositor in Liq.modify

medium

Makers can permanently lock JIT penalty revenue from the protocol treasury

medium

Denial of service for makers as any above-range partial liquidity reduction via adjustMaker

medium

Maker adding small liquidity can trigger full-position JIT penalty on long-term LPs

medium

Takers can underpay interest by exceeding 100% utilization, harming makers

Aug '25

USG - Tangent

USG - Tangent

8.78 USDC • 2 total findings • Sherlock • HeckerTrieuTien

#60

high

An attacker can steal victim collateral

medium

First depositor after zero-supply window will capture retroactive emissions from reward pool

Jul '25

Allbridge Core Yield

Allbridge Core Yield

150.46 USDC • 1 total finding • Sherlock • HeckerTrieuTien

bronze

medium

Attacker can inflate share price and drain deposits from PortfolioToken users in PortfolioToken. _subDepositRewardsPoolCheck

Malda

Malda

57.86 USDC • 2 total findings • Sherlock • HeckerTrieuTien

#35

medium

MixedPriceOracleV4 will mis-detect price divergence and revert operations for protocol users in MixedPriceOracleV4. _getLatestPrice

medium

Authorized Rebalancer EOA will cause denial-of-service for rebalancing on a (dstChainId, token) pair

pike-tapio-monrepo

pike-tapio-monrepo

1,071.76 USDC • 2 total findings • Cantina • HeckerTrieuTien

#8

medium

Finding not yet public.

medium

Finding not yet public.

Mellow Flexible Vaults

Mellow Flexible Vaults

313.13 USDC • 3 total findings • Sherlock • HeckerTrieuTien

#21

medium

SignatureRedeemQueue will revert ETH redemptions for users in SignatureRedeemQueue

medium

Non-whitelisted sender can bypass transfer whitelist, blocking legitimate transfer in ShareManager.updateChecks

medium

Disallowed asset in subvault will revert redeem, denying withdrawals in BasicRedeemHook.callHook

Cap

Cap

1,332.73 USDC • 1 total finding • Sherlock • HeckerTrieuTien

#6

medium

Zero Interest Rate Attack Due to Uninitialized Multiplier Due utilizationData.multiplier

DeBank

DeBank

118.22 USDC • Sherlock • HeckerTrieuTien

#25

Notional Exponent

Notional Exponent

380.40 USDC • 3 total findings • Sherlock • HeckerTrieuTien

#18

high

Any user will permanently disable withdrawals for all users

medium

Any user will block multi-token withdrawals for WETH-based vault depositors on CurveConvex2Token.unstakeAndExitPool

medium

Any user can permanently lock withdrawal funds of LP users - AbstractSingleSidedLP.finalizeAndRedeemWithdrawRequest

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

187.96 USDC • 3 total findings • Sherlock • HeckerTrieuTien

#32

high

Any EVM address can steal cross-chain refunds from legitimate recipients

high

Attacker can drain any ERC-20/ZRC-20 held by GatewayTransferNative, stealing users’ funds

medium

Library mis-read the flag non-zero byte on decompressAccounts

May '25

primev-validator-registry

primev-validator-registry

0.18 USDC • 1 total finding • Cantina • HeckerTrieuTien

#6

high

Finding not yet public.

LEND

LEND

46.92 USDC • 7 total findings • Sherlock • HeckerTrieuTien

#43

high

Incorrect lToken-credit calculation in CoreRouter.supply()

high

Stale-rate payout error in CoreRouter.redeem()

high

Cross-Chain Liquidation Token Address Mismatch Vulnerability

high

Cross-Chain Router _checkLiquidationValid Liquidation Validation Bug

high

LEND Token Double-Claiming Vulnerability

high

_handleValidBorrowRequest in CrossChainRouter - Interest Calculation Bug

medium

Double Interest Calculation in CoreRouter.borrow

stability-contracts

stability-contracts

77.49 USDC • 1 total finding • Cantina • HeckerTrieuTien

#26

high

Finding not yet public.

jigsaw-contracts

jigsaw-contracts

247.62 USDC • 3 total findings • Cantina • HeckerTrieuTien

#29

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

superform-core

superform-core

40.13 USDC • 1 total finding • Cantina • HeckerTrieuTien

#37

high

Finding not yet public.

mystic-monorepo

mystic-monorepo

328.77 USDC • 3 total findings • Cantina • HeckerTrieuTien

#12

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

mighty-contracts

mighty-contracts

0.15 USDC • 1 total finding • Cantina • HeckerTrieuTien

#100

high

Finding not yet public.

infinifi-protocol

infinifi-protocol

60.4 USDC • 1 total finding • Cantina • HeckerTrieuTien

#34

high

Finding not yet public.

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

1,274.07 USDC • 1 total finding • Code4rena • hecker_trieu_tien

#7

high

Precision loss in `toPackedFloat` function when mantissa is in range - (`MAX_M_DIGIT_NUMBER`, `MIN_L_DIGIT_NUMBER`)

Feb '25

Virtuals Protocol

Virtuals Protocol

230.73 USDC • 3 total findings • Code4rena • hecker_trieu_tien

#33

high

Lack of Access Control in `AgentNftV2::addValidator()` Enables Unauthorized Validator Injection and Causes Reward Accounting Inconsistencies

high

Public `ServiceNft::updateImpact` call leads to cascading issue

medium

Precision loss in priceALast, priceBLass