https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

MysteryAuditor

Contact Me

High

11

Total

Medium

9

Total

$2.10K

Total Earnings

#1084 All Time

8x

Payouts

silver

1x

2nd Places

regular

3x

Top 10

regular

5x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Jul '25

Allbridge Core Yield

Allbridge Core Yield

549.27 USDC • 1 total finding • Sherlock • MysteryAuditor

silver

medium

deposit() doesn't have slippage check

May '25

LayerEdge - Staking

LayerEdge - Staking

778.85 USDC • 1 total finding • Sherlock • MysteryAuditor

#4

high

The staker at the boundary remains in tier2 in certain case

Apr '25

mighty-contracts

mighty-contracts

68.3 USDC • 4 total findings • Cantina • MysteryAuditor

#36

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

458.74 USDC • 1 total finding • Code4rena • MysteryAuditor

#13

high

Early 72-digit adjustment in sqrt will lead to incorrect result exponent calculation

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • MysteryAuditor

#18

medium

Attacker can dilute reward mechanism by invoking `notifyRewardAmount()`

Feb '25

THORWallet

THORWallet

0 USDC • 1 total finding • Code4rena • MysteryAuditor

#10

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Core Contracts

Core Contracts

156.35 usdc • 5 total findings • CodeHawks • crazymysteryauditor

#117

high

Reward manipulation vulnerability in StabilityPool

high

Attackers can get most of RAACToken rewards by withdrawing dust amount from StabilityPool multiple times

high

Stability pool does not consider RToken balance increase when DEToken is withdrawn

medium

Incorrect utilization rate forces protocol to issue maximum rewards indefinitely

medium

`ReserveLibrary.getNormalizedDebt` doesn't return normalized debt

Jan '25

Plaza Finance

Plaza Finance

84.01 USDC • 6 total findings • Sherlock • MysteryAuditor

#38

high

Users can claim coupons without engaging in protocol activities due to the absence of a minimum duration between `create()` and `redeem()`

high

`Pool.transferReserveToAuction()` reverts due to incorrect usage of index for current auction

high

The fee calculation which the protocol claims is incorrect and this could unfair to users

medium

User funds can be lost during `joinBalancerAndPredeposit()` access

medium

The state variable `BondToken.globalPool` is updated incorrectly via `Pool.startAuction()`

medium

The `BondToken.increaseIndexedAssetPeriod()` involves incorrect logic for updating state variable `globalPool`