https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/b3503f16-cd35-485a-9cb8-3bd771b9e1c3.jpg

LeFy

Security Researcher

Contact Me

High

7

Total

Medium

23

Total

$117.73K

Total Earnings

#83 All Time

7x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

4x

Top 10

All

Sherlock

Code4rena

Cantina

Jul '25

Allbridge Core Yield

Allbridge Core Yield

150.46 USDC • 1 total finding • Sherlock • LeFy

bronze

medium

Inflation attack possible through depositRewards()

Feb '25

Blend V2 Audit + Certora Formal Verification

Blend V2 Audit + Certora Formal Verification

603.49 USDC • 4 total findings • Code4rena • rapid

#21

high

A reserve's `d_supply` is incorrectly updated and stored after flash loan execution

medium

Pools Outside of the Reward Zone can keep receiving Blend Tokens

medium

Missing update_rz_emis_data Calls in draw and donate Functions Lead to Incorrect Emissions Distribution

medium

Sensitive disclosure affecting V1

Dec '24

story-protocol

story-protocol

113,763.07 USDC • 17 total findings • Cantina • blitz

silver

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

1,115.22 USDC • 3 total findings • Sherlock • LeFy

#5

high

Flawed formula for calculating vote price allows for stealing funds from the protocol

medium

Slashing timeLock not implemented and lets user about to be slashed unvouch all the vouches making slashing have no impact

medium

Lack of slippage protection during selling of votes will cause loss to the users

Oct '24

Ethos Network Social Contracts

Ethos Network Social Contracts

1,911.58 USDC • 2 total findings • Sherlock • LeFy

bronze

medium

Reregistering an already deleted address is not implemented correctly

medium

A malicious compromised address of a profile can claim malicious attestations to a profile

Jul '24

MakerDAO Endgame

MakerDAO Endgame

149.87 USDC • Sherlock • LeFy

#95

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

41.85 USDC • 3 total findings • Sherlock • LeFy

#41

high

Users will always be able to vote even if their remaining locktime is less than _periodDuration

medium

BribeRewarder.sol does not handle tokens with transfer fees

medium

No MinimumLockDuration in Mlumstaking.sol lets anyone stake and steal rewards