https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/9533a98f-c769-4d98-9ed7-b78d858c1500.jpg

farman1094

Security Researcher

Contact Me

High

12

Total

Medium

14

Total

$69.45K

Total Earnings

#153 All Time

10x

Payouts

gold

2x

1st Places

silver

2x

2nd Places

bronze

1x

3rd Places

All

Sherlock

Code4rena

Cantina

CodeHawks

Immunefi

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

6.73 OP • 3 total findings • Sherlock • farman1094

#41

high

All the rewards which is unclaimed will be lost every time stake/unstake called.

high

Due to vulnerability in `SuperDCAListing` fees cannot be collected for native pair pools

medium

`mintRate` update will lead to disruption in reward calculation!

Aug '25

Flare - FAsset

Flare - FAsset

35,821.63 USDC • 1 total finding • Code4rena • farman1094

silver

medium

Agent underlying balance can be inflated, which cannot be prove-able to challenge it as illegal.

Neutrl Protocol

Neutrl Protocol

941.02 USDC • 1 total finding • Sherlock • farman1094

gold

medium

`FULL_RESTRICTED_STAKER_ROLE` restriction Bypass: Restricted Accounts Can Stake NUSD

Jul '25

Attackathon | Plume Network

Attackathon | Plume Network

2,795 USDC • 9 total findings • Immunefi • farman1094

#15

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

low

Finding not yet public.

May '25

Audit Comp | Flare | FAssets

Audit Comp | Flare | FAssets

10,583 • 3 total findings • Immunefi • farman1094

bronze

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

Aegis.im YUSD

Aegis.im YUSD

185.77 OP • 2 total findings • Sherlock • farman1094

silver

high

Incorrect Insurance Fee Accounting in approveRedeemRequest Leads to Collateral Over-Redemption

medium

Malicious user can create DOS for `requestRedeem` using `AegisMinting::withdrawRedeemRequest`

liquidity-book-vaults

liquidity-book-vaults

313.81 USDC • 3 total findings • Cantina • farman1094

#16

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Feb '25

Liquidity Management

Liquidity Management

0.66 usdc • 1 total finding • CodeHawks • farman1094

#55

low

Incorrect Token Price Validation in KeeperProxy

Jan '25

Plaza Finance

Plaza Finance

805.55 USDC • 4 total findings • Sherlock • farman1094

#14

high

Incorrect LevETH Redeem Rate Due to BondETH Market Rate and LevETH Rate Comparison, Leading to Trader Losses

high

Malicious Actor can Exploit the Pool Reserve using BondETH and Coupon Issuance Mechanism

high

The pool can be manipulated for financial gain, by fluctuating the supply of tokens.

medium

Flawed Security Mechanism in BondETH Withdrawal: Ineffective Safeguards Against Pool Manipulation

Dec '24

Flex Perpetuals

Flex Perpetuals

17,996.59 USDC • 1 total finding • Code4rena • farman1094

gold

medium

Most of the FTC rewards can be taken by single entity.