https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/1dc6b8da-a68a-4224-9ff3-e7d99ec2f7de.jpg

Oxsadeeq

Security Researcher

Security Reseacher {Always securing the Web} and Also interested in politics

Contact Me

High

7

Total

Medium

9

Total

$961.00

Total Earnings

#1310 All Time

14x

Payouts

regular

1x

Top 10

regular

5x

Top 25

regular

6x

Top 50

All

Sherlock

Code4rena

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

2.74 USDC • 2 total findings • Sherlock • Oxsadeeq

#68

medium

Unsafe use of `transferFrom()` with `IERC20

medium

Lack of validation for CrossChainMessages to the `GatewayCrossChain` would lead to loss of user funds

Dec '24

Lambo.win

Lambo.win

0 USDC • 1 total finding • Code4rena • Oxsadeeq

#36

high

Minting zero tokens when underlyingToken is not Ether in cashIn()

Nov '24

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

4.26 USDC • Sherlock • Oxsadeeq

#59

Aug '24

Winnables Raffles

Winnables Raffles

33.86 USDC • 2 total findings • Sherlock • Oxsadeeq

#21

high

A malicious actor could cancel a raffle in such a way that results in loss of reward tokens on the PrizeManager contract

medium

An admin could withdraw a raffle's winner prize if the reward is an ERC20 Token.

May '24

Munchables

Munchables

0.01 USDC • 1 total finding • Code4rena • Oxsadeeq

#16

high

Invalid validation allows users to unlock early

Jan '24

Curves

Curves

4.24 USDC • 4 total findings • Code4rena • Oxsadeeq

#106

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

onBalanceChange causes previously unclaimed rewards to be cleared

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

Nov '23

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

690.37 USDC • 1 total finding • Code4rena • Oxsadeeq

#9

high

Owner cannot withdraw all interest due to wrong calculation of accrued interest in WithdrwaCarry

Oct '23

NextGen

NextGen

0 USDC • 1 total finding • Code4rena • Oxsadeeq

#115

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

Ethena Labs

Ethena Labs

161.8 USDC • 1 total finding • Code4rena • Oxsadeeq

#23

medium

Soft Restricted Staker Role can withdraw stUSDe for USDe

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

38.61 USDC • Code4rena • Oxsadeeq

#51

Aug '23

Tangible Caviar

Tangible Caviar

0.03 USDC • Code4rena • Oxsadeeq

#87

Jul '23

Tapioca DAO

Tapioca DAO

20.42 USDC • 1 total finding • Code4rena • Oxsadeeq

#91

high

Ability to steal user funds and increase collateral share infinitely in BigBang and Singularity

May '23

Maia DAO Ecosystem

Maia DAO Ecosystem

5.2 USDC • 1 total finding • Code4rena • Oxsadeeq

#70

medium

Lack of slippage protection can lead to significant loss of user funds

Index

Index

0.17 USDC • 1 total finding • Sherlock • Oxsadeeq

#25

medium

DOS due to the use of deprecated function