https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/1ba7a786-7eb2-4bbc-840c-795a89a4ec72.jpg

TopStar

Security Researcher

Contact Me

High

10

Total

Medium

6

Total

$521.00

Total Earnings

#1471 All Time

11x

Payouts

regular

2x

Top 25

regular

3x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

May '25

LEND

LEND

4.30 USDC • 1 total finding • Sherlock • TopStar

#100

high

Logical error in LendStorage.borrowWithInterest

Apr '25

mighty-contracts

mighty-contracts

0.07 USDC • 1 total finding • Cantina • Top88Star

#115

high

Finding not yet public.

Feb '25

Core Contracts

Core Contracts

37.15 usdc • 7 total findings • CodeHawks • topstar

#210

high

Multiple issues from unnecessary balance increase calculation in DebtToken.mint

high

Incorrect Debt Token Accounting Due to Multiple Scaling Issues

medium

[H-2] Lack of Emergency Pause in `BaseGauge::stake` and `BaseGauge::withdraw

medium

Users Can Lose Funds and Collateral by Repaying Loans After Liquidation Grace Period Expiry

medium

FeeCollector stakeholders may receive less fee distribution due to unnecessarily precision loss

medium

Users Cannot Remove Their Own Boost Delegation, Causing Potential Lock-In

low

`FeeCollector::updateFeeType` wrong fee share validation leads to impossible update for some fee types

Jan '25

Part 2

Part 2

47.63 usdc • 1 total finding • CodeHawks • topstar

#57

high

Vaults weth reward is not distributed correctly

Aug '24

Phi

Phi

0.19 USDC • 1 total finding • Code4rena • TopStar

#54

high

Exposed `_removeCredIdPerAddress` & `_addCredIdPerAddress` allows anyone to cause issues to current holders as well as upcoming ones

zetachain-protocol

zetachain-protocol

324.32 USDC • 1 total finding • Cantina • Top88Star

#36

medium

Finding not yet public.

Tadle

Tadle

0.00 USDC • 1 total finding • CodeHawks • topstar

#175

high

Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function

Jul '24

TraitForge

TraitForge

0.01 USDC • 2 total findings • Code4rena • TopStar

#88

high

The maximum number of generations is infinite

high

Wrong minting logic based on total token count across generations

Zaros Part 1

Zaros Part 1

6.08 USDC • 1 total finding • CodeHawks • topstar

#92

medium

A malicious User can DOS all offchain orders making them unexecutable and leaving the protocol in an insolvent state. Also all offchain Trades can also be DOSed for honest parties that do not meet the fillorder requirements (no try and catch)

Biconomy: Nexus

Biconomy: Nexus

30.16 USDC • 1 total finding • CodeHawks • topstar

#18

low

Create account from `RegistryFactory` contract reverts due to unsorted external `attesters[]`

Jun '24

Notional Leveraged Vaults: Pendle PT and Vault Incentives

Notional Leveraged Vaults: Pendle PT and Vault Incentives

71.22 USDC • 1 total finding • Sherlock • TopStar

#14

high

Slippage protection not handled in `Ethena::_sellStakedUSDe()`