https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/501f096a-409a-46ca-ad17-a11eefdfd8d9.jpeg

Wojack

Security Researcher

Smart Contract Auditor & Web3 Security Researcher Solidity | Rust | Move | Vyper www.linkedin.com/in/wojack0x0

Contact Me

High

3

Total

Medium

11

Total

$101.00

Total Earnings

#2168 All Time

11x

Payouts

regular

1x

Top 10

regular

5x

Top 25

regular

7x

Top 50

All

Sherlock

Code4rena

Mar '26

Current Finance

Current Finance

17.27 USDC • 3 total findings • Sherlock • Wojack

#21

high

Inconsistent oracle usage during liquidations (EMA for health, Spot for payout) traps underwater positions and maximizes protocol bad debt

medium

Finding Title: Cross-segment accounting flaw in `RateLimiter` enables low-cost griefing DoS on Asset Borrow and Withdraw flows

medium

Finding Title: Incorrect debt scope validation in `handle_debt_auto_deleverage` allows Whitelisted Liquidators to execute unwarranted ADL liquidations on healthy users

Jan '26

OpenCover Insured Vaults

OpenCover Insured Vaults

0.11 USDC • Sherlock • Wojack

#153

Hotstuff

Hotstuff

0.15 USDC • Sherlock • Wojack

#99

Findings not publicly available for private contests.

Flying Tulip

Flying Tulip

0.60 USDC • Sherlock • Wojack

#226

Dec '25

Rujira

Rujira

0.02 USDC • 2 total findings • Code4rena • Wojack

#115

medium

Finding not yet public.

medium

Finding not yet public.

Nov '25

Brix Money

Brix Money

47.7 USDC • 1 total finding • Code4rena • Wojack

#8

medium

Cross-chain unstake and fast redeem operations fail due to minAmountLD not accounting for LayerZero dust removal

SukukFi

SukukFi

0 USDC • 1 total finding • Code4rena • Wojack

#20

medium

Finding not yet public.

stNXM by EaseDeFi

stNXM by EaseDeFi

0.79 USDC • 3 total findings • Sherlock • Wojack

#47

high

Reliance on Uniswap V3 spot price in totalAssets allows share price manipulation via flash loans

medium

Duplicate tranche IDs in stakeNxm cause double-counting of assets, leading to totalAssets inflation and potential vault drainage

medium

Strict APY sanity check in StNxmOracle causes permanent Denial of Service for Morpho operations shortly after deployment

Oct '25

Reflector V3

Reflector V3

0 USDC • 2 total findings • Code4rena • Wojack

#16

high

`set_invocation_costs_config()` fails to authorize admin allowing anyone to set invocation costs

medium

`twap()` under-charges for multi-period queries due to hardcoded `periods=1`

Index Fun Order Book

Index Fun Order Book

0.62 USDC • 1 total finding • Sherlock • Wojack

#15

medium

An authorized matcher can steal all protocol fees by changing the treasury address

Hybra Finance

Hybra Finance

34.43 USDC • 1 total finding • Code4rena • Wojack

#28

medium

CL gauge accepts unverified pools, allowing malicious pool to brick distribution