https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/501f096a-409a-46ca-ad17-a11eefdfd8d9.jpeg

Wojack

Security Researcher

Smart Contract Auditor & Web3 Security Researcher Solidity | Rust | Move | Vyper www.linkedin.com/in/wojack0x0

Contact Me

High

5

Total

Medium

12

Total

$166.00

Total Earnings

#2050 All Time

14x

Payouts

regular

2x

Top 10

regular

6x

Top 25

regular

9x

Top 50

All

Sherlock

Code4rena

Apr '26

Clear Macro by Superfluid

Clear Macro by Superfluid

1.94 USDC • Sherlock • Wojack

#102

Mar '26

Current Finance

Current Finance

17.27 USDC • 3 total findings • Sherlock • Wojack

#21

high

Inconsistent oracle usage during liquidations (EMA for health, Spot for payout) traps underwater positions and maximizes protocol bad debt

medium

Finding Title: Cross-segment accounting flaw in `RateLimiter` enables low-cost griefing DoS on Asset Borrow and Withdraw flows

medium

Finding Title: Incorrect debt scope validation in `handle_debt_auto_deleverage` allows Whitelisted Liquidators to execute unwarranted ADL liquidations on healthy users

Jan '26

Olas

Olas

28.72 USDC • 2 total findings • Code4rena • Wojack

#49

high

Finding not yet public.

medium

Finding not yet public.

Fluid DEX v2

Fluid DEX v2

34.00 USDC • 1 total finding • Sherlock • Wojack

#12

high

Fluid MoneyMarket Internal Accounting Mismatch Leads to Insolvency

OpenCover Insured Vaults

OpenCover Insured Vaults

0.11 USDC • Sherlock • Wojack

#153

Hotstuff

Hotstuff

0.15 USDC • Sherlock • Wojack

#99

Findings not publicly available for private contests.

Flying Tulip

Flying Tulip

0.60 USDC • Sherlock • Wojack

#226

Dec '25

Rujira

Rujira

0.02 USDC • 2 total findings • Code4rena • Wojack

#51

medium

Finding not yet public.

medium

Finding not yet public.

Nov '25

Brix Money

Brix Money

47.7 USDC • 1 total finding • Code4rena • Wojack

#8

medium

Cross-chain unstake and fast redeem operations fail due to minAmountLD not accounting for LayerZero dust removal

SukukFi

SukukFi

0 USDC • 1 total finding • Code4rena • Wojack

#8

medium

The unregistering of vaults can be DoSed by a malicious user.

stNXM by EaseDeFi

stNXM by EaseDeFi

0.79 USDC • 3 total findings • Sherlock • Wojack

#47

high

Reliance on Uniswap V3 spot price in totalAssets allows share price manipulation via flash loans

medium

Duplicate tranche IDs in stakeNxm cause double-counting of assets, leading to totalAssets inflation and potential vault drainage

medium

Strict APY sanity check in StNxmOracle causes permanent Denial of Service for Morpho operations shortly after deployment

Oct '25

Reflector V3

Reflector V3

0 USDC • 2 total findings • Code4rena • Wojack

#16

high

`set_invocation_costs_config()` fails to authorize admin allowing anyone to set invocation costs

medium

`twap()` under-charges for multi-period queries due to hardcoded `periods=1`

Index Fun Order Book

Index Fun Order Book

0.62 USDC • 1 total finding • Sherlock • Wojack

#15

medium

An authorized matcher can steal all protocol fees by changing the treasury address

Hybra Finance

Hybra Finance

34.43 USDC • 1 total finding • Code4rena • Wojack

#28

medium

CL gauge accepts unverified pools, allowing malicious pool to brick distribution