https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

MysteryAuditor

Contact Me

High

14

Total

Medium

11

Total

$5.62K

Total Earnings

#862 All Time

12x

Payouts

silver

1x

2nd Places

regular

5x

Top 10

regular

7x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Jan '26

Hotstuff

Hotstuff

188.34 USDC • Sherlock • MysteryAuditor

#15

Findings not publicly available for private contests.

Nov '25

stNXM by EaseDeFi

stNXM by EaseDeFi

0.51 USDC • 1 total finding • Sherlock • MysteryAuditor

#49

medium

No existance check of `trancheId` in the `_stakeNxm` function

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

0.02 OP • 2 total findings • Sherlock • MysteryAuditor

#50

high

The `stake()` and `unstake()` erases the accrued rewards

medium

The reward will be distributed when `totalStakedAmount = 0`

Dango DEX

Dango DEX

1,633.06 USDC • 1 total finding • Sherlock • MysteryAuditor

#10

high

Splitting swap in multiple small amounts will produce more output

Jul '25

Allbridge Core Yield

Allbridge Core Yield

549.27 USDC • 1 total finding • Sherlock • MysteryAuditor

silver

medium

deposit() doesn't have slippage check

May '25

LayerEdge - Staking

LayerEdge - Staking

778.85 USDC • 1 total finding • Sherlock • MysteryAuditor

#4

high

The staker at the boundary remains in tier2 in certain case

Apr '25

mighty-contracts

mighty-contracts

68.3 USDC • 4 total findings • Cantina • MysteryAuditor

#36

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

2,157.5 USDC • 2 total findings • Code4rena • HappyTop0603

#4

high

Early 72-digit adjustment in sqrt will lead to incorrect result exponent calculation

high

Precision loss in `toPackedFloat` function when mantissa is in range - (`MAX_M_DIGIT_NUMBER`, `MIN_L_DIGIT_NUMBER`)

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • MysteryAuditor

#18

medium

Attacker can dilute reward mechanism by invoking `notifyRewardAmount()`

Feb '25

THORWallet

THORWallet

0 USDC • 1 total finding • Code4rena • HappyTop0603

#10

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Core Contracts

Core Contracts

156.35 usdc • 5 total findings • CodeHawks • crazymysteryauditor

#117

high

Reward manipulation vulnerability in StabilityPool

high

Attackers can get most of RAACToken rewards by withdrawing dust amount from StabilityPool multiple times

high

Stability pool does not consider RToken balance increase when DEToken is withdrawn

medium

Incorrect utilization rate forces protocol to issue maximum rewards indefinitely

medium

`ReserveLibrary.getNormalizedDebt` doesn't return normalized debt

Jan '25

Plaza Finance

Plaza Finance

84.01 USDC • 6 total findings • Sherlock • MysteryAuditor

#38

high

Users can claim coupons without engaging in protocol activities due to the absence of a minimum duration between `create()` and `redeem()`

high

`Pool.transferReserveToAuction()` reverts due to incorrect usage of index for current auction

high

The fee calculation which the protocol claims is incorrect and this could unfair to users

medium

User funds can be lost during `joinBalancerAndPredeposit()` access

medium

The state variable `BondToken.globalPool` is updated incorrectly via `Pool.startAuction()`

medium

The `BondToken.increaseIndexedAssetPeriod()` involves incorrect logic for updating state variable `globalPool`