https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/d22280b4-fcde-4a68-baff-91e1376817be.jpg

boredpukar

Web3 Security Researcher

security, data, AI, and other stuffs.

Contact Me

High

9

Total

Medium

16

Total

$2.02K

Total Earnings

#1145 All Time

23x

Payouts

gold

1x

1st Places

regular

4x

Top 10

regular

7x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Nov '25

stNXM by EaseDeFi

stNXM by EaseDeFi

10.96 USDC • 4 total findings • Sherlock • boredpukar

#30

high

Critical Accounting Manipulation via `removeTokenIdAtIndex` Allows Owner to Steal User Principal

high

Spot Price Dependency in `dexBalances` Allows Share Price Manipulation

medium

Fragile APY Sanity Check in `StNxmOracle` Causes Early Deployment Denial of Service

medium

Accounting Manipulation and Theft via Duplicate Tranche Tracking in `stakeNxm`

Aug '25

USG - Tangent

USG - Tangent

2.34 USDC • 1 total finding • Sherlock • boredpukar

#64

high

Untrusted authorizer in migration flows allows anyone to drain a user’s collateral via `migrateFrom`

Neutrl Protocol

Neutrl Protocol

941.02 USDC • 1 total finding • Sherlock • boredpukar

gold

medium

FULL-Restricted Staker Can Still Stake by Depositing to an Unrestricted Receiver

Yield Basis

Yield Basis

114.27 USDC • 2 total findings • Sherlock • boredpukar

#9

medium

`Factory::set_gauge_controller` has inverted guard

medium

Missing accounting update in `claim()` allows unbounded repeat claims by the recipient

Morpheus

Morpheus

6.61 USDC • 1 total finding • Code4rena • boredpukar

#10

medium

Same heartbeat for multiple price feeds is vulnerable

Jul '25

Mellow Flexible Vaults

Mellow Flexible Vaults

7.11 USDC • 3 total findings • Sherlock • boredpukar

#37

high

Consensus Threshold Bypass via Duplicate Signer Entries

medium

Incorrect Indexing in `DepositQueue.cancelDepositRequest()` Corrupts Fenwick-Tree Accounting

medium

Transfer-Whitelist Logic Inversion in `ShareManager.updateChecks`

DeBank

DeBank

6.11 USDC • Sherlock • boredpukar

#87

Notional Exponent

Notional Exponent

240.82 USDC • 3 total findings • Sherlock • boredpukar

#24

high

Missing Slippage Protection in `PendlePT_sUSDe._executeInstantRedemption` Enables Sandwich Attacks

medium

Hard-Coded Mainnet WETH Address Breaks All Non-Mainnet Deployments

medium

Zero-Cooldown Withdrawals in EthenaWithdrawRequestManager Permanently Strand Users’ USDe

May '25

mystic-monorepo

mystic-monorepo

4.93 USDC • 1 total finding • Cantina • boredpukar

#71

medium

Finding not yet public.

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

344.05 USDC • 1 total finding • Code4rena • boredpukar

#20

high

Early 72-digit adjustment in sqrt will lead to incorrect result exponent calculation

Feb '25

THORWallet

THORWallet

0.35 USDC • 1 total finding • Code4rena • boredpukar

#8

high

MergeTgt has no handling if TGT_TO_EXCHANGE is exceeded during the exchange period

Liquidity Management

Liquidity Management

0.66 usdc • 1 total finding • CodeHawks • iampukar

#55

low

Incorrect Token Price Validation in KeeperProxy

Dec '24

SecondSwap

SecondSwap

4.28 USDC • 1 total finding • Code4rena • boredpukar

#54

medium

Creator of one vesting plan can affect vesting plans created by other users.

Nov '24

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

5.67 USDC • Sherlock • boredpukar

#58

hyperlend

hyperlend

43.12 USDC • 1 total finding • Cantina • boredpukar

#16

high

Finding not yet public.

Oct '24

Dria

Dria

13.52 USDC • 1 total finding • CodeHawks • iampukar

#50

medium

BuyerAgent Batch Purchase Failure Due to Asset Transfer or Approval Revocation

Jul '24

TraitForge

TraitForge

203.35 USDC • 1 total finding • Code4rena • boredpukar

#26

medium

Potential Uninitialized `entropySlots` Reading in `getNextEntropy`, Causing 0 Entropy Mint

Mar '24

Revert Lend

Revert Lend

6.61 USDC • 1 total finding • Code4rena • boredpukar

#70

medium

V3Oracle susceptible to price manipulation

Feb '24

Rio Network

Rio Network

33.27 USDC • 1 total finding • Sherlock • boredpukar

#30

medium

Fixed Amount of Gas Sent in Call May Be Insufficient.

AI Arena

AI Arena

8.81 USDC • Code4rena • boredpukar

#129

Jan '24

Decent

Decent

0.09 USDC • 1 total finding • Code4rena • boredpukar

#56

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

Nov '23

Kelp DAO | rsETH

Kelp DAO | rsETH

2.76 USDC • Code4rena • boredpukar

#54

Apr '23

Frankencoin

Frankencoin

22.6 USDC • Code4rena • boredpukar

#66