https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/793f7e78-de2a-4e15-8239-a8eb27839fd2.png

bratwork

Security Researcher

Security Researcher | Crypto auditor and malware analyst

Contact Me

High

8

Total

Medium

14

Total

$655.00

Total Earnings

#1640 All Time

14x

Payouts

regular

2x

Top 10

regular

9x

Top 25

regular

12x

Top 50

All

Sherlock

Code4rena

Cantina

Mar '26

Revert Finance

Revert Finance

154.42 USDC • 1 total finding • Cantina • bratwork

#14

medium

Finding not yet public.

Chainlink Payment Abstraction V2

Chainlink Payment Abstraction V2

0 USDC • 1 total finding • Code4rena • happykilling

#11

medium

Finding not yet public.

Current Finance

Current Finance

17.16 USDC • 3 total findings • Sherlock • bratwork

#23

high

Liquidation authorizes on EMA prices but seizes collateral on unchecked spot prices

medium

Deposit Cap Bypass When `cash_reserve` Is Non-Zero

medium

Deposits in a Later Limiter Segment Do Not Release Withdraw Capacity

Intuition

Intuition

340.67 USDC • 1 total finding • Code4rena • happykilling

#4

medium

Epoch-boundary checkpoints retroactively qualify for the previous epoch's rewards

Feb '26

Injective Peggy Bridge

Injective Peggy Bridge

44.12 USDC • 3 total findings • Code4rena • happykilling

#16

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jan '26

Olas

Olas

0 USDC • 1 total finding • Code4rena • happykilling

#58

high

Finding not yet public.

Fluid DEX v2

Fluid DEX v2

34.00 USDC • 1 total finding • Sherlock • bratwork

#12

high

Normal supply withdraw uses unclamped user amount for token transfer, allowing over-withdrawal beyond position balance

OpenCover Insured Vaults

OpenCover Insured Vaults

1.57 USDC • Sherlock • bratwork

#117

VII-Finance-Contracts

VII-Finance-Contracts

37.32 OP • 1 total finding • Cantina • bratwork

#26

high

Finding not yet public.

Dec '25

Panoptic: Next Core

Panoptic: Next Core

1.75 USDC • 2 total findings • Code4rena • happykilling

#32

high

BuilderWallet `init()` is unprotected/re-initializable, enabling takeover and theft of builder fees

medium

`RiskEngine::_getRequiredCollateralAtTickSinglePosition()` Fails to Accumulate Credits Across Multiple Legs, Leading to Potential Erroneous Liquidations

Rujira

Rujira

1.07 USDC • 4 total findings • Code4rena • happykilling

#46

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Monolith Stablecoin Factory

Monolith Stablecoin Factory

5.20 USDC • 1 total finding • Sherlock • bratwork

#25

medium

Long Inactivity Permanently Freezes Interest Accrual

Nov '25

SukukFi

SukukFi

0 USDC • 1 total finding • Code4rena • happykilling

#8

high

Missing access control in `WERC7575Vault` allows unauthorized withdrawals

Swafe

Swafe

18.47 USDC • 2 total findings • Code4rena • happykilling

#22

medium

Guardian share replay overwrite causes persistent recovery DoS (missing session binding)

medium

Marking a backup makes recovery impossible (recover list never queried)