Banner
https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/af1b7f35-d7df-4cf5-918b-566fa39fa977.jpg

fromeo_016

Security Researcher

Smart Contract Auditor👾 | Auditing protocols one bug at a time👨🏾‍💻

Contact Me

High

5

Total

Medium

12

Total

$770.00

Total Earnings

#1395 All Time

5x

Payouts

regular

1x

Top 10

regular

3x

Top 25

regular

4x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

29.96 USDC • 2 total findings • Sherlock • fromeo_016

#42

medium

Gas Token Swap Exhausts User Funds

medium

Protocol will misdirect refunds to truncated Bitcoin addresses

May '25

aave-aptos

aave-aptos

175.25 GHO • 1 total finding • Cantina • fromeo016

#10

medium

Finding not yet public.

Apr '25

mezo-monorepo

mezo-monorepo

487.73 USDC • 3 total findings • Cantina • fromeo016

#22

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Feb '25

Core Contracts

Core Contracts

77.62 usdc • 10 total findings • CodeHawks • fromeo_016

#162

high

Wrong amount is minted to user when they deposit into the lending pool

high

Multiple issues from unnecessary balance increase calculation in DebtToken.mint

high

RToken is Not Interest Bearing Due to Broken Liquidity Index Calculation

high

Double Usage Index Scaling in StabilityPool Liquidation Inflates Required CRVUSD Balance

high

Incorrect Debt Scaling Leading to Protocol Solvency Risk

medium

LendingPool deposits do not work with CurveVault due to lack of funds

medium

Workingsupply would always be overwritten in boostcontroller.sol impacting reward calculations

medium

hardcoded baseamount in Updateuserboost fucntion causes users with small token holdings to receive higher boosts relative to their holdings t

medium

Permanent boost inflation through delegation removal in Boostcontroller.sol

medium

Flawed Boost Multiplier Calculation Always Yields Maximum Boost

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • fromeo_016

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions