https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

MysteryAuditor

Contact Me

High

13

Total

Medium

10

Total

$3.73K

Total Earnings

#944 All Time

10x

Payouts

silver

1x

2nd Places

regular

4x

Top 10

regular

6x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

0.02 OP • 2 total findings • Sherlock • MysteryAuditor

#50

high

The `stake()` and `unstake()` erases the accrued rewards

medium

The reward will be distributed when `totalStakedAmount = 0`

Dango DEX

Dango DEX

1,633.06 USDC • 1 total finding • Sherlock • MysteryAuditor

#10

high

Splitting swap in multiple small amounts will produce more output

Jul '25

Allbridge Core Yield

Allbridge Core Yield

549.27 USDC • 1 total finding • Sherlock • MysteryAuditor

silver

medium

deposit() doesn't have slippage check

May '25

LayerEdge - Staking

LayerEdge - Staking

778.85 USDC • 1 total finding • Sherlock • MysteryAuditor

#4

high

The staker at the boundary remains in tier2 in certain case

Apr '25

mighty-contracts

mighty-contracts

68.3 USDC • 4 total findings • Cantina • MysteryAuditor

#36

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

458.74 USDC • 1 total finding • Code4rena • MysteryAuditor

#13

high

Early 72-digit adjustment in sqrt will lead to incorrect result exponent calculation

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • MysteryAuditor

#18

medium

Attacker can dilute reward mechanism by invoking `notifyRewardAmount()`

Feb '25

THORWallet

THORWallet

0 USDC • 1 total finding • Code4rena • MysteryAuditor

#10

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Core Contracts

Core Contracts

156.35 usdc • 5 total findings • CodeHawks • crazymysteryauditor

#117

high

Reward manipulation vulnerability in StabilityPool

high

Attackers can get most of RAACToken rewards by withdrawing dust amount from StabilityPool multiple times

high

Stability pool does not consider RToken balance increase when DEToken is withdrawn

medium

Incorrect utilization rate forces protocol to issue maximum rewards indefinitely

medium

`ReserveLibrary.getNormalizedDebt` doesn't return normalized debt

Jan '25

Plaza Finance

Plaza Finance

84.01 USDC • 6 total findings • Sherlock • MysteryAuditor

#38

high

Users can claim coupons without engaging in protocol activities due to the absence of a minimum duration between `create()` and `redeem()`

high

`Pool.transferReserveToAuction()` reverts due to incorrect usage of index for current auction

high

The fee calculation which the protocol claims is incorrect and this could unfair to users

medium

User funds can be lost during `joinBalancerAndPredeposit()` access

medium

The state variable `BondToken.globalPool` is updated incorrectly via `Pool.startAuction()`

medium

The `BondToken.increaseIndexedAssetPeriod()` involves incorrect logic for updating state variable `globalPool`