https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/5dbcb2db-bfb2-4bf5-8561-d7cec293f380.jpg

Ziusz

Bounty Hunter

SEE YOU SPACE COWBOY...

Contact Me

High

13

Total

Medium

1

Solo

17

Total

$14.33K

Total Earnings

#506 All Time

19x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

regular

8x

Top 10

All

Sherlock

Code4rena

Cantina

Oct '25

Index Fun Order Book

Index Fun Order Book

70.67 USDC • 1 total finding • Sherlock • Ziusz

#10

medium

Emergency fallback resolves wrong epoch on timed markets permanently freezing funds

Sequence

Sequence

40.59 USDC • 1 total finding • Code4rena • Ziusz

#11

medium

Session signatures replay across wallets due to missing wallet binding

3Jane

3Jane

1,111.73 USDC • Sherlock • Ziusz

#9

Findings not publicly available for private contests.

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

29.45 OP • 3 total findings • Sherlock • Ziusz

#36

high

Cashback pays for time before campaign start

high

Staker can wipe pending emissions for a token by resetting bucket index

medium

First staker capture mints emissions for idle time to the pool

Dango DEX

Dango DEX

3,477.63 USDC • 2 total findings • Sherlock • Ziusz

#8

medium

User can brick a new pool via zero or one-sided initial provide

medium

User can pause all auctions by overflow in mid-price average

Ammplify

Ammplify

51.21 USDC • 3 total findings • Sherlock • Ziusz

#51

high

Missing canonical Uniswap V3 pool verification allows arbitrary token theft from the diamond via malicious pool

medium

ViewWalker misroutes unpaid X to Y breaking `queryAssetBalances` correctness

medium

NFTManager `burnAsset` always triggers JIT penalty on removal

Aug '25

USG - Tangent

USG - Tangent

2.34 USDC • 1 total finding • Sherlock • Ziusz

#64

high

Attacker can spoof ControlTower in migrateFrom to steal user collateral

kuru-contracts

kuru-contracts

605.39 USDC • 1 total finding • Cantina • Ziusz

#31

high

Finding not yet public.

Neutrl Protocol

Neutrl Protocol

941.02 USDC • 1 total finding • Sherlock • Ziusz

gold

medium

FULL_RESTRICTED user can bypass staking restriction by depositing to different receiver

Yield Basis

Yield Basis

69.47 USDC • 1 total finding • Sherlock • Ziusz

#10

medium

Factory gauge controller can only be set to zero address due to assert logic error

Jul '25

Malda

Malda

1,035.54 USDC • 6 total findings • Sherlock • Ziusz

#13

high

Rebalancer can steal all funds through EverclearBridge

medium

MixedPriceOracleV4 decimal mismatch breaks oracle redundancy system

medium

`WrapAndSupply` fails to forward ETH for gas fees breaking the cross-chain functionality

medium

Blacklisted users can withdraw funds via delegates bypassing blacklist enforcement

medium

DoS on window rollover can block liquidity rebalancing

medium

EverclearBridge never pulls tokens from Rebalancer causing complete rebalancing DoS

USDaf-v2

USDaf-v2

1,250 USDC • Cantina • Ziusz

silver

Jun '25

Symbiotic Relay

Symbiotic Relay

2,569.06 USDC • 3 total findings • Sherlock • Ziusz

#8

medium

Unbounded loop in PersistentSet allows any user to cause permanent DoS on core view functions

medium

Unregistered operators retain voting power through registered vaults causing inconsistent state

medium

State Inconsistency in OperatorsWhitelist allows bypassing access control

DODO Cross-Chain DEX

DODO Cross-Chain DEX

0.20 USDC • 1 total finding • Sherlock • Ziusz

#73

high

Flawed authorization logic in `claimRefund` allows theft of non-EVM refunds

May '25

LEND

LEND

9.60 USDC • 3 total findings • Sherlock • Ziusz

#87

high

System will prevent valid Cross-Chain Liquidations due to Irrelevant Check in `_checkLiquidationValid`

high

System will understate liabilities for Borrowers leading to Protocol Insolvency by bad condition in `borrowWithIntest`

high

Incorrect LToken Accounting in `CoreRouter.supply()` can lead to discrepancy in User's favor

aera-v3

aera-v3

1,289.75 USDC • 1 total finding • Cantina • Ziusz

#4

high

Finding not yet public.

Audit 507

Audit 507

56.02 USDC • Code4rena • Ziusz

#25

jigsaw-contracts

jigsaw-contracts

67.91 USDC • 1 total finding • Cantina • Ziusz

#56

high

Finding not yet public.

Apr '25

Burve

Burve

1,657.16 USDC • 1 total finding • Sherlock • Ziusz

#12

high

User can drain value from Protocol/LPs by receiving excess shares during swaps into appreciating ERC4626 vaults