https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/23d2663a-da88-49c1-b61d-6e5b55002711.jpg

Lamsya

Security Researcher

🔥Catching Bugs 🔥

High

8

Total

Medium

21

Total

$2.84K

Total Earnings

#982 All Time

12x

Payouts

regular

2x

Top 10

regular

7x

Top 25

regular

9x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

May '25

LEND

LEND

4.63 USDC • 2 total findings • Sherlock • Lamsya

#99

high

Unrestricted Multiple Claims of LEND Rewards Due to Missing Claim Tracking

high

Cross-Chain Borrow Accounting Bypass Allows Unlimited Borrowing

aera-v3

aera-v3

1,289.75 USDC • 1 total finding • Cantina • Lamsy

#4

high

Finding not yet public.

Apr '25

mezo-monorepo

mezo-monorepo

84.46 USDC • 3 total findings • Cantina • Lamsy

#39

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Kinetiq

Kinetiq

9.35 USDC • 1 total finding • Code4rena • Lamsy

#33

medium

Inconsistent State Restoration in `cancelWithdrawal` Function

Feb '25

velvet-v4

velvet-v4

420.94 USDC • 3 total findings • Cantina • Lamsy

#19

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Core Contracts

Core Contracts

94.82 usdc • 16 total findings • CodeHawks • lamsy

#148

high

Wrong amount is minted to user when they deposit into the lending pool

high

Delegation Boost Not Usable by Delegatees

high

Users Can Overwrite Existing Locks in veRAACToken Resulting in Permanent Loss of Funds

high

Users can borrow more assets than they have deposited as collateral

medium

Missing Vote Frequency Control in GaugeController

medium

There is no logic checking for RAACNFT price staleness before minting it

medium

Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations

medium

Emergency revoke in RAACReleaseOrchestrator will freeze revoked RAAC tokens in orchestrator

medium

`GaugeController::distributeRewards` can be called multiple times by anyone, leading to excessive reward distribution

medium

hardcoded baseamount in Updateuserboost fucntion causes users with small token holdings to receive higher boosts relative to their holdings t

medium

Token Accounting Mismatch Between tick() and mintRewards() in RAACMinter

medium

Emergency Withdrawal Remains Active After Cancellation

medium

`RAACReleaseOrchestrator::emergencyRevoke()` fails to update `categoryUsed`, leading to token lockup and incorrect accounting

low

Incorrect Initialization of minBoost in BaseGauge Constructor Breaks Core Contract Functionality

low

Incorrect Timestamp Tracking in RAACHousePrice contract

low

`emergencyUnlockEnabled` Is Never Used, Rendering “Emergency Unlock” Ineffective

Jan '25

Next Generation

Next Generation

227.2 USDC • 2 total findings • Code4rena • Lamsy

#8

high

Cross-Chain Signature Replay Attack Due to User-Supplied `domainSeparator` and Missing Deadline Check

medium

Lack of deadline check in forwarded request

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • Lamsy

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

IQ AI

IQ AI

3.58 USDC • 1 total finding • Code4rena • Lamsy

#16

medium

Ineffective proposal threshold validation allows setting arbitrary high values

ton-pool-contracts

ton-pool-contracts

694.39 USDC • 1 total finding • Cantina • Lamsy

#11

medium

Finding not yet public.

Ignite

Ignite

15.29 usdc • CodeHawks • lamsy

#21

Dec '24

SecondSwap

SecondSwap

0.03 USDC • 1 total finding • Code4rena • Lamsy

#66

medium

Incorrect referral fee calculations