https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/526c93d4-0b6d-4016-8a2e-413ddf1bc844.jpg

Kirkeelee

Security Researcher

Web3 security researcher.

Contact Me

High

15

Total

Medium

18

Total

$21.59K

Total Earnings

#375 All Time

33x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

bronze

3x

3rd Places

All

Sherlock

Code4rena

Cantina

CodeHawks

Hats Finance

Aug '25

3Jane

3Jane

Collaborative Audit • Sherlock • Kirkeelee

Jul '25

Mellow Flexible Vaults

Mellow Flexible Vaults

390.16 USDC • 1 total finding • Sherlock • Kirkeelee

#20

medium

stETH edge case in transfer rounding can cause denial of service for depositors and redeemers.

succinct-network

succinct-network

294.63 USDC • 1 total finding • Cantina • kirkeelee

#25

medium

Finding not yet public.

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

9.15 USDC • 1 total finding • Sherlock • Kirkeelee

#58

medium

Users may not receive refunds for native tokens if a cross-chain transaction is reverted.

May '25

LEND

LEND

405.65 USDC • 10 total findings • Sherlock • Kirkeelee

#12

high

A cross-chain user can drain protocol funds by exploiting token decimal mismatches.

high

A user can supply collateral via flashloan/flashmint, initiate a cross-chain borrow, and redeem collateral in a single transaction to drain protocol funds.

high

Users can repeatedly claim the same LEND rewards due to lack of reset after claim.

high

User can evade liquidation and bridge funds by exploiting cross-chain borrow/collateral invariant

high

Liquidation can fail permanently due to incorrect `destEid` in `findCrossChainCollateral`, causing liquidator funds to be stuck.

high

Repayment logic incorrectly updates same-chain borrow balances for cross-chain borrows.

high

LEND rewards are calculated after balance updates, leading to inaccurate and unfair reward distribution.

high

A user can over-borrow on multiple chains by exploiting asynchronous cross-chain borrow requests

medium

A user can drain the contract’s ETH balance by spamming cross-chain borrow requests without supplying any collateral.

medium

Borrow limit check may be overly restrictive due to redundant interest scaling in borrow calculation.

Native Smart Contract V2

Native Smart Contract V2

1,292.72 USDC • Sherlock • Kirkeelee

#11

Findings not publicly available for private contests.

Apr '25

Seamless Protocol - Leverage Tokens

Seamless Protocol - Leverage Tokens

Collaborative Audit • Sherlock • Kirkeelee

Mar '25

StarkWare Perps

StarkWare Perps

23.92 USDC • Code4rena • Kirkeelee

#23

Feb '25

Blend V2 Audit + Certora Formal Verification

Blend V2 Audit + Certora Formal Verification

122.06 USDC • 2 total findings • Code4rena • Kirkeelee

#25

medium

Pools Outside of the Reward Zone can keep receiving Blend Tokens

medium

Missing update_rz_emis_data Calls in draw and donate Functions Lead to Incorrect Emissions Distribution

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • Kirkeelee

bronze

medium

`maxTokenAmountPerUser` limit can be bypassed when currency token has less decimals than the launch token.

Liquidity Management

Liquidity Management

1,324.65 usdc • 2 total findings • CodeHawks • kirkeelee

#7

medium

PerpetualVault can be completely bricked

medium

ADL can result in unwrapped ETH as output which is not handled

Jan '25

Part 2

Part 2

81.92 usdc • 2 total findings • CodeHawks • kirkeelee

#48

high

Vaults weth reward is not distributed correctly

high

Unclaimed Rewards Loss Due to Missing Validation in `VaultRouterBranch.stake()`

Plaza Finance

Plaza Finance

5.50 USDC • 2 total findings • Sherlock • Kirkeelee

#82

high

Large redeems before fee claims reduce collectible fees

medium

BalancerRouter.sol does not return excess user funds at certain conditions.

FlatMoney v2 Update

FlatMoney v2 Update

325.31 USDC • Sherlock • Kirkeelee

#10

Findings not publicly available for private contests.

Dec '24

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

0.18 OP • 1 total finding • Sherlock • Kirkeelee

#66

high

Anyone can steal USDT from the protocol using the redeemUSDT function.

Nov '24

Chiliz Chain System Contracts

Chiliz Chain System Contracts

195.98 USDC • Sherlock • Kirkeelee

#13

Findings not publicly available for private contests.

Oct '24

Covalent - EWM Light Client

Covalent - EWM Light Client

453.76 USDC • Sherlock • Kirkeelee

bronze

Findings not publicly available for private contests.

Index x Morpho Leverage Integration

Index x Morpho Leverage Integration

12,000 USDC • 1 total finding • Sherlock • Kirkeelee

gold

medium

_calculateMaxBorrowCollateral function will revert in extreme market conditions leading to liquidations.

AXION

AXION

162.74 USDC • 2 total findings • Sherlock • Kirkeelee

#9

medium

V3AMO.sol will not work with some of the protocols it is aimed to integrate with.

medium

The protocol is not compliant with ERC-1504

Sep '24

uniswap-v4

uniswap-v4

330.08 USDC • Cantina • kirkeelee

#49

Aug '24

Cork Protocol

Cork Protocol

99.45 USDC • 1 total finding • Sherlock • Kirkeelee

#12

medium

Wrong accounting in case of using stETH as RA due to 1-2 Wei loss per transfer.

Midas - Instant Minter/Redeemer

Midas - Instant Minter/Redeemer

809.83 USDC • 1 total finding • Sherlock • Kirkeelee

#7

medium

Incorrect pointer set in the ```initialize()``` function leads to broken functionality of RedemptionVaultWithBUIDL.sol

Jul '24

MakerDAO Endgame

MakerDAO Endgame

240.35 USDC • Sherlock • Kirkeelee

#86

Velocimeter

Velocimeter

438.92 USDC • 1 total finding • Sherlock • Kirkeelee

#21

high

The function ```disable_max_lock``` in VotingEscrow.sol doesn't handle the case when the nft being removed is the last item in the array.

May '24

Euler-v2

Euler-v2

694 USDC • Cantina • kirkeelee

#44

Kwenta x Perennial Integration Update

Kwenta x Perennial Integration Update

44.54 USDC • Sherlock • Kirkeelee

#7

LoopFi

LoopFi

386.08 USDC • 1 total finding • Code4rena • Kirkeelee

bronze

high

Availability of deposit invariant can be bypassed

Apr '24

xKeeper

xKeeper

831.96 USDC • 1 total finding • Sherlock • Kirkeelee

silver

medium

OpenRelay.sol does not account for the Layer1 gas fees used in the transaction while calculating the fee to be paid to the relayer.

Feb '24

Tokemak

Tokemak

519 USDC • Hats • 0xker2

#7

Althea Liquid Infrastructure

Althea Liquid Infrastructure

25.73 USDC • 1 total finding • Code4rena • Kirkeelee

#32

medium

Distribution can be bricked, and double claims by a few holders are possible when owner calls `LiquidInfrastructureERC20::setDistributableERC20s`

Jan '24

Ion Protocol

Ion Protocol

86.5 USDC • Hats • 0xker2

#11

SYMM IO

SYMM IO

0.00 USDC • Sherlock • Kirkeelee

#44

Dec '23

Footium Update

Footium Update

0.00 USDC • Sherlock • Kirkeelee

#44

Jul '23

Beam

Beam

0.00 USDC • Sherlock • Kirkeelee

#41

May '23

USSD - Autonomous Secure Dollar

USSD - Autonomous Secure Dollar

0.00 USDC • 1 total finding • Sherlock • Kirkeelee

#91

high

Wrong price feed contract address used in the constructor of the StableOracleWBTC.sol.