https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_1.png

coin2own

Security Researcher

Contact Me

High

6

Total

Medium

12

Total

$1.75K

Total Earnings

#1173 All Time

9x

Payouts

regular

1x

Top 10

regular

3x

Top 25

regular

9x

Top 50

All

Sherlock

Sep '25

Ammplify

Ammplify

138.63 USDC • 4 total findings • Sherlock • coin2own

#37

high

Use of Manipulatable Spot Price Oracle for Value Calculation Leads to Direct Theft of User Funds

medium

Copy-Paste Error in `ViewWalker` Breaks Fee Calculation for Half the Protocol's Positions

medium

`calculateLiquidityOffset` Logic Causes Denial of Service and Poor User Experience for Concentrated Liquidity Positions

medium

JIT Liquidity Penalty is Bypassed via `collectFees` Function, Nullifying Protection Mechanism

Aug '25

USG - Tangent

USG - Tangent

1,144.65 USDC • 2 total findings • Sherlock • coin2own

#4

medium

Asset/Share Confusion in `burn` Function Allows Theft of All Underlying Capital

medium

Precision Loss in Interest Rate Formula Leads to Incorrect Rates and Denial of Service

Jul '25

Malda

Malda

0.20 USDC • 1 total finding • Sherlock • coin2own

#46

medium

Flawed Logic in Transfer Rate-Limiting Mechanism Leads to Denial of Service

Mellow Flexible Vaults

Mellow Flexible Vaults

2.67 USDC • 2 total findings • Sherlock • coin2own

#41

high

Duplicate Signatures Bypass Consensus Threshold

medium

Inverted Transfer Whitelist Logic Allows Unauthorized Transfers and Blocks Authorized Ones

DeBank

DeBank

89.01 USDC • Sherlock • coin2own

#32

Notional Exponent

Notional Exponent

64.94 USDC • 1 total finding • Sherlock • coin2own

#40

medium

Division by Zero in `finalizeAndRedeemWithdrawRequest` Permanently Locks Funds for Partial LP Withdrawals

Jun '25

Symbiotic Relay

Symbiotic Relay

16.16 USDC • 1 total finding • Sherlock • coin2own

#11

medium

Gas Denial of Service (DoS) in `PersistentSet.values()` and `valuesAt()` Due to Unbounded Iteration Over Historical Elements

DODO Cross-Chain DEX

DODO Cross-Chain DEX

120.28 USDC • 2 total findings • Sherlock • coin2own

#34

high

Authorization Bypass in claimRefund Allows Theft of All Pending Refunds for Non-EVM Addresses

medium

Incompatible Encoding and Decoding Functions in AccountEncoder Library Lead to Malformed Cross-Chain Messages for Solana

May '25

LEND

LEND

177.87 USDC • 5 total findings • Sherlock • coin2own

#20

high

Incorrect maxLiquidationAmount Calculation in Cross-Chain Liquidation Validation Prevents Legitimate Liquidations

high

Incorrect Principal Update in _handleValidBorrowRequest Understates Cross-Chain Debt Obligation on Collateral Chain

high

Stale Collateral Data in Cross-Chain Borrow Validation (_handleBorrowCrossChainRequest) Leads to Risk of Undercollateralized Loans

medium

maxClose Calculation in liquidateBorrowAllowedInternal Uses Stale Principal, Unduly Restricting Liquidation Repayment Amount

medium

Flawed and Redundant Secondary Liquidity Check in borrow Function May Incorrectly Deny Valid Borrows