Security Researcher
High
Total
Medium
Solo
Total Earnings
#715 All Time
Payouts
3rd Places
Top 10
Top 25
All
Sherlock
Nov '25
294.19 USDC • 2 total findings • Sherlock • dandan
#8
high
Owner can use fake staking pool to steal all NXM in vault
medium
Tokens from arNXM vault are charged admin fee
12.54 USDC • 1 total finding • Sherlock • dandan
maxDeposit() and maxMint() does not check for totalSupply <= MAX_SHARES
Sep '25
4,468.29 USDC • 3 total findings • Sherlock • dandan
#6
Missing slippage protection in provide liquidity means no way to protect against price fluctuation.
Attacker can exploit thin liquidity in xyk pool to save on fees.
Protocol loses out on fees when swapping via unbalanced deposits
Jul '24
2,945.04 USDC • 3 total findings • Sherlock • dandan
Attacker can exercise option tokens to repeatedly relock victim's lp tokens.
User loses unclaimed rewards when merging tokens.
Voting power does not decay when calculating shares of flow emissions if the user does not vote again.