Security Researcher
High
Total
Medium
Total Earnings
#1126 All Time
Payouts
1st Places
2nd Places
Top 10
All
Sherlock
Sep '25
2.82 USDC • 1 total finding • Sherlock • Mishkat6451
#74
medium
Hardcoded TAKER_VAULT_ID (80085) can collide with real user IDs which leads funds to be mis-credited
Aug '25
95.48 USDC • 2 total findings • Sherlock • Mishkat6451
#46
Incorrect assumption that one (1) Pendle Standard Yield (SY) token is equal to one (1) Yield Token when computing the price in the oracle
Attacker can indefinitely delay users’ streamed rewards by repeatedly calling processRewards with tiny injected rewards
941.02 USDC • 1 total finding • Sherlock • Mishkat6451
FULL_RESTRICTED users can still initiate deposits (stake)
Jul '25
941.75 USDC • 1 total finding • Sherlock • Mishkat6451
Missing Slippage Protection on deposit Function Allows for Sandwich Attacks
2.67 USDC • 2 total findings • Sherlock • Mishkat6451
#41
high
Single Signer Can Bypass Multi-Signature Threshold Using Duplicate Signatures
Inverted Whitelist Logic in ShareManager Freezes Funds of Whitelisted Accounts
Jun '25
16.16 USDC • 1 total finding • Sherlock • Mishkat6451
#11
Gas-Griefing DoS on `view` Functions