https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/71e9e424-38b8-4dc3-ad58-c330f415807d.jpg

Hueber

Security Researcher

Contact Me

High

6

Total

Medium

10

Total

$2.69K

Total Earnings

#988 All Time

8x

Payouts

regular

4x

Top 25

regular

5x

Top 50

All

Sherlock

Code4rena

CodeHawks

May '25

LEND

LEND

39.06 USDC • 8 total findings • Sherlock • Hueber

#50

high

User is able to borrow more than his collateral amount

high

User can steal tokens from cross-chain borrowing

high

User will receive less interest than he should when redeeming his collateral

high

Incorrect accounting of LTokens during supply of underlying tokens

medium

Incorrect calculation of borrowed amount when borrowing

medium

Max repay amount calculation is wrong during liquidation

medium

Bad actor can spend the balance of the CrossChainRouter contract

medium

Use safeTransfer instead of transfer

Mar '25

StarkWare Perps

StarkWare Perps

1,729.33 USDC • Code4rena • Hueber

#13

Jan '25

Next Generation

Next Generation

3.55 USDC • 1 total finding • Code4rena • Hueber

#15

medium

Lack of deadline check in forwarded request

Plaza Finance

Plaza Finance

21.19 USDC • 3 total findings • Sherlock • Hueber

#68

high

Auction cannot be ended

medium

MarketRate will never be used if it comes from Chainlink

medium

User cannot claim from Distributor when there is a failed auction

Sep '24

Staking

Staking

891.54 USDC • CodeHawks • hueber

#23

Aug '24

Fjord Token Staking

Fjord Token Staking

0.19 USDC • 1 total finding • CodeHawks • hueber

#20

medium

[H-01] Auction tokens will be lost forever when auction ends without bids

Apr '24

NOYA

NOYA

4.59 USDC + NOYA stars • 1 total finding • Code4rena • Hueber

#103

medium

Using the same heartbeat for multiple price feeds

DYAD

DYAD

4 USDC • 2 total findings • Code4rena • Hueber

#107

high

Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine

medium

Incorrect deployment / missing contract will break functionality