Banner
https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/e35fc6db-56ab-49ed-b201-697009bfc82f.jpg

OhmOudits

Security Researcher

We believe your protocol is our sacred mantra.

Contact Me

High

6

Total

Medium

10

Total

$4.22K

Total Earnings

#952 All Time

6x

Payouts

bronze

1x

3rd Places

regular

2x

Top 10

regular

5x

Top 25

All

Sherlock

Code4rena

Cantina

Mar '26

Current Finance

Current Finance

17.34 USDC • 4 total findings • Sherlock • OhmOudits

#19

high

Oracle policy mismatch between normal operations and liquidation enables path-dependent liquidation outcomes

medium

Deposit cap check double-subtracts reserves, enabling cap bypass and underflow aborts

medium

Borrow ADL trigger uses global reserve debt instead of per-eMode-group debt

medium

Rate limiter `reduce_outflow` only updates the current segment, enabling low-cost borrow-capacity griefing

Dec '25

Rujira

Rujira

1.04 USDC • 2 total findings • Code4rena • OhmOudits

#95

high

Finding not yet public.

medium

Finding not yet public.

Oct '25

Reflector V3

Reflector V3

198.29 USDC • 4 total findings • Code4rena • OhmOudits

#7

high

`set_invocation_costs_config()` fails to authorize admin allowing anyone to set invocation costs

medium

`twap()` under-charges for multi-period queries due to hardcoded `periods=1`

medium

Systematic Overcharge in prices and x_prices: Fee Charged for Requested Records While Return is Capped at 20

medium

Expiration vector length mismatch causes panic in extend_ttl() when assets are added with zero initial expiration period

Sep '25

Dango DEX

Dango DEX

10.58 USDC • 1 total finding • Sherlock • OhmOudits

#21

medium

`provide_liquidity` allows zero-token deposits, enabling DOS attack on pool initialization

Aug '25

solayer-bridge

solayer-bridge

3,037.32 USDC • 3 total findings • Cantina • OhmOudits

bronze

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Apr '25

ZetaChain Cross-Chain

ZetaChain Cross-Chain

959.81 USDC • 2 total findings • Sherlock • OhmOudits

#12

high

any non whitelisted token can deposit into pda using `deposit_spl_token` and `deposit_spl_token_and_call`

medium

Missing `sender` in signature message hash enables vulnerabilities in `handle_sol` Function