https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

Sparrow_Jac

Security Researcher

Contact Me

High

13

Total

Medium

29

Total

$14.46K

Total Earnings

#500 All Time

43x

Payouts

silver

1x

2nd Places

bronze

1x

3rd Places

regular

10x

Top 10

All

Sherlock

Code4rena

Cantina

CodeHawks

Oct '25

3Jane

3Jane

289.78 USDC • Sherlock • Sparrow_Jac

#12

Findings not publicly available for private contests.

Hybra Finance

Hybra Finance

315.79 USDC • Code4rena • Sparrow

#17

Jul '25

Malda

Malda

0.20 USDC • 1 total finding • Sherlock • Sparrow_Jac

#46

medium

Max-transfer window reset blocks liquidity

Mellow Flexible Vaults

Mellow Flexible Vaults

213.35 USDC • 3 total findings • Sherlock • Sparrow_Jac

#26

high

Compromised signer will execute unauthorized actions

medium

Disallowed token permanently locks existing balances

medium

Transfer whitelist blocks good transfers and allows bad ones

DeBank

DeBank

15.07 USDC • Sherlock • Sparrow_Jac

#74

Jun '25

solaxy

solaxy

1,349.39 USDC • 1 total finding • Cantina • Sparrow

bronze

medium

Finding not yet public.

May '25

LEND

LEND

23.82 USDC • 2 total findings • Sherlock • Sparrow_Jac

#64

high

Incorrect Token/Amount in Cross-Chain Liquidation Repayment

medium

# Flawed Logic in Borrow Function's Secondary Liquidity Check

Audit 507

Audit 507

54 USDC • Code4rena • Sparrow

#26

superform-core

superform-core

40.13 USDC • 1 total finding • Cantina • Sparrow

#37

high

Finding not yet public.

Apr '25

Burve

Burve

54.68 USDC • 2 total findings • Sherlock • Sparrow_Jac

#27

high

`removeValueSingle` protocol fee bypass allows users to withdraw full amount (no tax deducted)

high

Netting Bug in E4626.sol commit Function

mighty-contracts

mighty-contracts

0.23 USDC • 2 total findings • Cantina • Sparrow

#93

high

Finding not yet public.

high

Finding not yet public.

Mar '25

StarkWare Perps

StarkWare Perps

315.79 USDC • Code4rena • Sparrow

#20

Feb '25

Blend V2 Audit + Certora Formal Verification

Blend V2 Audit + Certora Formal Verification

4,178.13 USDC • 1 total finding • Code4rena • Sparrow

#8

medium

Edge case breaks APR cap calculation and leads to excessive fee extraction from the pool

THORWallet

THORWallet

165.79 USDC • Code4rena • Sparrow

#4

Virtuals Protocol

Virtuals Protocol

947.37 USDC • Code4rena • Sparrow

#8

Initia Cosmos

Initia Cosmos

663.16 USDC • Code4rena • Sparrow

#7

Core Contracts

Core Contracts

15.30 usdc • 7 total findings • CodeHawks • sparrow

#259

high

ZENO Token Redemption Returns Negligible USDC Amount Compared to Purchase Price

high

Voting Power Snapshot Missing

medium

Missing Vote Frequency Control in GaugeController

medium

Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check

medium

Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations

medium

`RAACReleaseOrchestrator::emergencyRevoke()` fails to update `categoryUsed`, leading to token lockup and incorrect accounting

medium

Cordinated group of attacker can artificially lower quorum threshold during active proposals forcing malicious proposals to pass without true majority support.

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • Sparrow

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

IQ AI

IQ AI

3.58 USDC • 1 total finding • Code4rena • Sparrow

#16

medium

Ineffective proposal threshold validation allows setting arbitrary high values

daao-contracts

daao-contracts

58.72 USDC • 1 total finding • Cantina • Sparrow

#61

high

Finding not yet public.

Aave DIVA Wrapper

Aave DIVA Wrapper

28.54 usdc • 1 total finding • CodeHawks • sparrow

#7

low

The Aave pool is hardcoded

infrared-contracts

infrared-contracts

634.72 USDC • 1 total finding • Cantina • Sparrow

#40

medium

Finding not yet public.

Pump Science

Pump Science

221.05 USDC • Code4rena • Sparrow

#7

Dec '24

QuantAMM

QuantAMM

0.82 op • 1 total finding • CodeHawks • sparrow

#78

medium

quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.

Flex Perpetuals

Flex Perpetuals

862.48 USDC • 1 total finding • Code4rena • Sparrow

silver

medium

Missing slippage protection in `AerodromeDexter.sol` `swapExactTokensForTokens()`

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

4.01 OP • 2 total findings • Sherlock • Sparrow_Jac

#35

medium

Inverted Price Staleness Check in PythOracle Accepts Stale Prices

medium

Denial of Service Risk due to Improper Use of `safeApprove()`

Nov '24

MANTRA DEX

MANTRA DEX

12.22 USDC • 1 total finding • Code4rena • Sparrow

#22

medium

`withdraw_liquidity` lacks slippage protection

Concrete

Concrete

635.79 USDC • Code4rena • Sparrow

#25

Chainlink

Chainlink

1,473.68 USDC • Code4rena • Sparrow

#5

Oct '24

Kleidi

Kleidi

0 USDC • Code4rena • Sparrow

#12

Aug '24

Chakra

Chakra

0.02 USDT • 1 total finding • Code4rena • Sparrow

#67

high

SettlementSignatureVerifier is missing check for duplicate validator signatures

Superposition

Superposition

1.26 USDC • 1 total finding • Code4rena • Sparrow

#32

medium

_onTransferReceived() does not work as intended

Phi

Phi

21.42 USDC • 1 total finding • Code4rena • Sparrow

#38

high

Signature replay in `createArt` allows to impersonate artist and steal royalties

zetachain-protocol

zetachain-protocol

104.48 USDC • 1 total finding • Cantina • Sparrow

#62

medium

Finding not yet public.

Axelar Network

Axelar Network

947.37 USDC • Code4rena • Sparrow

#5

Jul '24

LoopFi

LoopFi

220.95 USDC • 2 total findings • Code4rena • Sparrow

#33

medium

`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`

medium

`SwapAction.sol#balancerSwap` does not support native ETH as input token.

Optimism Superchain

Optimism Superchain

0 OP • Code4rena • Sparrow

#14

Biconomy: Nexus

Biconomy: Nexus

134.97 USDC • 1 total finding • CodeHawks • sparrow

#16

high

User may lose funds when creating Nexus account or executing user operations

May '24

Beanstalk: The Finale

Beanstalk: The Finale

142.21 USDC • 2 total findings • CodeHawks • sparrow

#30

medium

Incorrect Loop Counter Increment in `ReseedField` Contract

low

`BeanL1RecieverFacet#recieveL1Beans()` would never work

Olas

Olas

232.44 USDC • 1 total finding • Code4rena • Sparrow

#12

medium

Incorrect Handling of Last Nominee Removal in `removeNominee` Function

Predy

Predy

55.39 USDC • 3 total findings • Code4rena • Sparrow

#24

medium

incorrect price for negative ticks due to lack of rounding down

medium

Liquidity manipulation is possible when trading

medium

Chainlink's `latestRoundData` might return stale or incorrect results

Apr '24

Renzo

Renzo

0 USDC • Code4rena • Sparrow

#58

NOYA

NOYA

19.18 USDC + NOYA stars • 1 total finding • Code4rena • Sparrow

#82

medium

Chainlink connector doesn’t check for the Min / Max prices returned