Security Researcher
High
Total
Medium
Solo
Total Earnings
#730 All Time
Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Dec '25
1,654.62 USDC • 1 total finding • Sherlock • dandan
#6
high
Users can get stuck in paid debt mode and lose their entire collateral
Nov '25
294.19 USDC • 2 total findings • Sherlock • dandan
#8
Owner can use fake staking pool to steal all NXM in vault
medium
Tokens from arNXM vault are charged admin fee
12.54 USDC • 1 total finding • Sherlock • dandan
maxDeposit() and maxMint() does not check for totalSupply <= MAX_SHARES
Sep '25
4,468.29 USDC • 3 total findings • Sherlock • dandan
Missing slippage protection in provide liquidity means no way to protect against price fluctuation.
Attacker can exploit thin liquidity in xyk pool to save on fees.
Protocol loses out on fees when swapping via unbalanced deposits
Jul '24
2,945.04 USDC • 3 total findings • Sherlock • dandan
Attacker can exercise option tokens to repeatedly relock victim's lp tokens.
User loses unclaimed rewards when merging tokens.
Voting power does not decay when calculating shares of flow emissions if the user does not vote again.