https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/31eb1a84-becd-41de-8cc2-d0ca16589a3d.png

befree3x

Security Researcher

High

5

Total

Medium

1

Solo

10

Total

$6.00K

Total Earnings

#800 All Time

19x

Payouts

silver

1x

2nd Places

regular

2x

Top 10

regular

5x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Nov '25

stNXM by EaseDeFi

stNXM by EaseDeFi

40.91 USDC • 3 total findings • Sherlock • befree3x

#24

high

Uniswap V3 Spot Price dependency in `stNXM` accounting allows exchange rate manipulation and fund theft

medium

`StNxmOracle` will permanently DoS due to overly strict APY checks on short timeframes

medium

Missing Uniswap V3 cardinality initialization in `StNxmOracle` leads to permanent Denial of Service

Privacy Cash

Privacy Cash

9.52 USDC • Sherlock • befree3x

#49

Findings not publicly available for private contests.

Oct '25

Saffron Fixed Income Vaults

Saffron Fixed Income Vaults

13.77 USDC • Sherlock • befree3x

#50

3Jane

3Jane

77.00 USDC • Sherlock • befree3x

#18

Findings not publicly available for private contests.

Sep '25

Ammplify

Ammplify

9.66 USDC • 1 total finding • Sherlock • befree3x

#73

medium

Standalone NFTManager reads from its own empty storage instead of Diamond's, causing tokenURI to revert

Aug '25

USG - Tangent

USG - Tangent

37.97 USDC • 1 total finding • Sherlock • befree3x

#56

medium

WStable mints unbacked shares, leading to fund loss

Jul '25

Malda

Malda

4,388.29 USDC • 1 total finding • Sherlock • befree3x

silver

medium

Rebalancer can drain market funds via excessive bridge fees

DeBank

DeBank

3.42 USDC • Sherlock • befree3x

#97

Jun '25

Symbiotic Relay

Symbiotic Relay

16.16 USDC • 1 total finding • Sherlock • befree3x

#11

medium

Unbounded iteration over logically removed elements in `PersistentSet` could lead to gas DOS

DODO Cross-Chain DEX

DODO Cross-Chain DEX

0.20 USDC • 1 total finding • Sherlock • befree3x

#73

high

Anyone can steal pending refunds due to flawed recipient validation

May '25

LEND

LEND

16.97 USDC • 1 total finding • Sherlock • befree3x

#75

high

Stale collateral data risk in cross-chain borrow execution may lead to undercollateralized loans

Mar '25

badger-ebtc-bsm

badger-ebtc-bsm

14.85 USDC • 1 total finding • Cantina • befree3x

#31

high

Finding not yet public.

Jan '25

Aave v3.3

Aave v3.3

0.57 USDC • Sherlock • befree3x

#118

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

0.26 OP • 1 total finding • Sherlock • befree3x

#63

medium

Canceling an `OracleLess` order type is vulnerable to DOS

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

0.14 OP • 1 total finding • Sherlock • befree3x

#67

high

`updateDownsideProtected` can be called by anyone leading to incorrect downside protection records on CDS module

Nov '24

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

0.10 USDC • Sherlock • befree3x

#70

Debita Finance V3

Debita Finance V3

0.47 USDC • 1 total finding • Sherlock • befree3x

#56

medium

Anyone can delete all active lending offers without authorization

May '24

Sablier

Sablier

1,272.86 USDC • 1 total finding • CodeHawks • befree3x

#7

medium

Insufficient input validation on `SablierV2NFTDescriptor::safeAssetSymbol` allows an attacker to obtain stored XSS

Mar '24

Revert Lend

Revert Lend

92.11 USDC • 1 total finding • Code4rena • befree3x

#48

medium

Wrong global lending limit check in `_deposit` function