https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_9.png

dandan

Security Researcher

Contact Me

High

3

Total

Medium

1

Solo

6

Total

$7.72K

Total Earnings

#715 All Time

4x

Payouts

bronze

1x

3rd Places

regular

4x

Top 10

regular

4x

Top 25

All

Sherlock

Nov '25

stNXM by EaseDeFi

stNXM by EaseDeFi

294.19 USDC • 2 total findings • Sherlock • dandan

#8

high

Owner can use fake staking pool to steal all NXM in vault

medium

Tokens from arNXM vault are charged admin fee

Inverse Finance - Junior Tranche

Inverse Finance - Junior Tranche

12.54 USDC • 1 total finding • Sherlock • dandan

bronze

medium

maxDeposit() and maxMint() does not check for totalSupply <= MAX_SHARES

Sep '25

Dango DEX

Dango DEX

4,468.29 USDC • 3 total findings • Sherlock • dandan

#6

medium

Missing slippage protection in provide liquidity means no way to protect against price fluctuation.

medium

Attacker can exploit thin liquidity in xyk pool to save on fees.

medium

Protocol loses out on fees when swapping via unbalanced deposits

Jul '24

Velocimeter

Velocimeter

2,945.04 USDC • 3 total findings • Sherlock • dandan

#6

high

Attacker can exercise option tokens to repeatedly relock victim's lp tokens.

high

User loses unclaimed rewards when merging tokens.

medium

Voting power does not decay when calculating shares of flow emissions if the user does not vote again.