https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

SamuelTroyDomi

Security Researcher

Contact Me

High

10

Total

Medium

7

Total

$1.06K

Total Earnings

#1269 All Time

12x

Payouts

regular

1x

Top 10

regular

4x

Top 25

regular

6x

Top 50

All

Sherlock

Code4rena

CodeHawks

Jun '25

Superfluid Locker System

Superfluid Locker System

323.57 USDC • 1 total finding • Sherlock • SamuelTroyDomi

#8

high

`pump` functionality and purpose can be completely bypassed by lockers, completely avoiding the intention of the protocol to add buy pressure

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

0.05 USDC • Sherlock • SamuelTroyDomi

#92

Feb '25

Usual Labs

Usual Labs

0.62 USDC • Sherlock • SamuelTroyDomi

#53

Liquidity Management

Liquidity Management

43.87 usdc • 1 total finding • CodeHawks • fresh

#45

high

Deposits on long one leverage vault don't actually finalize the flow, leading to a Denial of Service (DoS)

Core Contracts

Core Contracts

104.50 usdc • 9 total findings • CodeHawks • fresh

#135

high

Users can borrow more assets than they have deposited as collateral

high

NFTs Get Permanently Locked in Stability Pool After Liquidation

high

RToken is Not Interest Bearing Due to Broken Liquidity Index Calculation

high

Interest Accrual Failure Due to Incorrect Scaling in RToken Implementation

medium

RToken.transferFrom() Does Not Scale User Balances Due to Stale Liquidity Index

medium

LendingPool deposits do not work with CurveVault due to lack of funds

medium

Inconsistent Scaling in RToken Transfer Functions

low

Lack of incentives for users to call LendingPool::initiateLiquidation allows extensive delay between when health factor dropped below threshold and when grace period starts

low

Dynamic emissions schedule based on system utilization doesn’t work

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • Samueltroydomi

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

IQ AI

IQ AI

243.25 USDC • 1 total finding • Code4rena • Samueltroydomi

#13

high

Adversary can win proposals with voting power as low as 4%

Part 2

Part 2

74.64 usdc • 2 total findings • CodeHawks • fresh

#51

high

Incorrect Credit Capacity Validation in `VaultRouterBranch.redeem` Enables Locked Collateral Drainage

high

Unclaimed Rewards Loss Due to Missing Validation in `VaultRouterBranch.stake()`

Plaza Finance

Plaza Finance

1.00 USDC • 1 total finding • Sherlock • SamuelTroyDomi

#96

medium

If Auction Fails, Some Bond Holders Each Period Will Never Be Able To Receive Coupon Payments Owed To Them

Ignite

Ignite

258.29 usdc • CodeHawks • fresh

#13

Dec '24

Alchemix Transmuter

Alchemix Transmuter

11.67 op • 2 total findings • CodeHawks • fresh

#26

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

low

Old router retains token allowance after update

SecondSwap

SecondSwap

2.81 USDC • 2 total findings • Code4rena • Samueltroydomi

#60

high

Users can claim more that their actual allotment

medium

maxSellPercent can be buypassed by selling previously bought vestings at a later time