https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/47c636b5-7999-4ce5-9fd3-48330b9c0f38.png

francoHacker

Security Researcher

"Passionate about blockchain since 2015. Believer in its power to change the world, rejecting fiat for trust in the blockchain."

Contact Me

High

4

Total

Medium

6

Total

$403.00

Total Earnings

#1665 All Time

16x

Payouts

regular

2x

Top 10

regular

6x

Top 25

regular

9x

Top 50

All

Sherlock

Code4rena

Sep '25

Ammplify

Ammplify

67.59 USDC • 1 total finding • Sherlock • francoHacker

#49

high

Critical Protocol Calculations Depend on a Manipulable Spot Price Oracle

Aug '25

Yield Basis

Yield Basis

69.47 USDC • 1 total finding • Sherlock • francoHacker

#10

medium

A bug in the `Factory` contract will prevent the admin from setting a valid `GaugeController`, permanently disabling protocol incentives for Liquidity Providers.

Jul '25

DeBank

DeBank

5.87 USDC • Sherlock • francoHacker

#89

Jun '25

Symbiotic Relay

Symbiotic Relay

16.16 USDC • 1 total finding • Sherlock • francoHacker

#11

medium

FrancoHacker Unbounded Loop in getVotingPowersAt Leads to Systemic Denial of Service

May '25

LEND

LEND

29.83 USDC • 3 total findings • Sherlock • francoHacker

#61

high

francoHacker - CrossChainRouter._handleLiquidationSuccess() Incorrectly Processes LayerZero Payload Data, Leading to Miscalculation of Debt Repayment After Successful Cross-Chain Liquidation

high

francoHacker - `CoreRouter` Uses Potentially Stale LToken Exchange Rate, Leading to Accounting Discrepancies and Risk of Value Leakage

high

francoHacker - Critical Cross-Chain Debt Misaccounting in `_handleDestRepayMessage` Leads to Protocol Value Leakage and Unreliable Liquidations

Audit 507

Audit 507

104.02 USDC • Code4rena • francoHacker

#20

Feb '25

THORWallet

THORWallet

0 USDC • 1 total finding • Code4rena • francoHacker

#10

medium

Improper Transfer Restrictions on Non-Bridged Tokens Due to Boolean Bridged Token Tracking, Allowing a DoS Attack Vector

Jan '25

Next Generation

Next Generation

3.55 USDC • 1 total finding • Code4rena • francoHacker

#15

medium

Lack of deadline check in forwarded request

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • francoHacker

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

Dec '22

Tigris Trade contest

Tigris Trade contest

1.15 USDC • 1 total finding • Code4rena • francoHacker

#64

medium

Centralization risks: owner can freeze withdraws and use timelock to steal all funds

Oct '22

Holograph contest

Holograph contest

0 USDC • Code4rena • francoHacker

#44

Sep '22

QuickSwap and StellaSwap contest

QuickSwap and StellaSwap contest

24.02 USDC • Code4rena • francoHacker

#65

VTVL contest

VTVL contest

9.09 USDC • Code4rena • francoHacker

#80

PartyDAO contest

PartyDAO contest

35.35 USDC • Code4rena • francoHacker

#67

Aug '22

Nouns DAO contest

Nouns DAO contest

16.66 USDC • Code4rena • francoHacker

#44

Fraxlend (Frax Finance) contest

Fraxlend (Frax Finance) contest

21.17 USDC • Code4rena • francoHacker

#70