https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

S3v3ru5

Security Researcher

Contact Me

High

6

Total

Medium

1

Solo

8

Total

$9.95K

Total Earnings

#548 All Time

4x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

3x

Top 10

All

Sherlock

Feb '25

Hyperlane Sealevel Audit - Wave 2

Hyperlane Sealevel Audit - Wave 2

Collaborative Audit • Sherlock • S3v3ru5

Oct '24

Orderly Solana Vault Contract

Orderly Solana Vault Contract

1,997.97 USDC • 2 total findings • Sherlock • S3v3ru5

bronze

high

Attacker can steal funds by depositing dummy tokens in Solana vault

high

Attacker can steal user funds by calling solana_vault::lz_receive with their token accounts

Sep '24

WOOFi Swap on Solana

WOOFi Swap on Solana

6,974.23 USDC • 3 total findings • Sherlock • S3v3ru5

silver

high

Swap function does not check `woopool_quote` is indeed a quote pool

medium

Attacker can prevent WooFi admin from adding additional base tokens

medium

State changes are overwritten during anchor serialization when two accounts are the same

Aug '24

Winnables Raffles

Winnables Raffles

797.93 USDC • 6 total findings • Sherlock • S3v3ru5

bronze

high

Missing validations on CCIP parameters in the `WinnablesTicketManager.cancelRaffle` and `propagateRaffleWinner` allows attackers to cause loss of funds

high

Attacker can cancel raffles before they can be created leading to DoS

high

Missing updates to `_lockedETH` state variable in the `WinnablesTicketManager.refundPlayer` function lead to loss of funds

medium

Admin can overwrite owner of the winning ticket using integer overflow

medium

WinnablesPrizeManager.setCCIPCounterpart function allows admins to send their own winner messages to the prize manager

medium

The `WinnablesTicket.ownerOf` function might always revert with Out-of-Gas for certain tickets leading to loss of funds

Sentiment V2

Sentiment V2

175.26 USDC • 3 total findings • Sherlock • S3v3ru5

#25

medium

Liquidation fee is charged on the total seized amount instead of the liquidator profit

medium

SuperPool is not ERC4626 compliant

medium

First deposit after rebalancing might receive shares worth of less value