Banner
https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/1f8f2473-53f5-44ce-817f-5a4b8f98fb15.jpg

ge6a

Security Researcher

Independent security researcher, 10+ years of experience in software development

Contact Me

High

15

Total

Medium

23

Total

$45.57K

Total Earnings

#192 All Time

30x

Payouts

gold

2x

1st Places

silver

3x

2nd Places

bronze

1x

3rd Places

All

Sherlock

Code4rena

CodeHawks

Apr '25

ZKP2P V2

ZKP2P V2

672.40 OP • Sherlock • ge6a

#5

Findings not publicly available for private contests.

Mar '25

Symmio, Staking and Vesting

Symmio, Staking and Vesting

1,928.19 USDC • 1 total finding • Sherlock • ge6a

silver

medium

Double spending attack in the Vesting contract

Dec '24

QuantAMM

QuantAMM

68.63 op • 5 total findings • CodeHawks • ge6a

#55

high

Fee Evasion via LP Token Transfer Resets Deposit Value

medium

quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.

medium

“Uplift Fee” Incorrectly Falls Back to Minimum Fee Due to Integer Division

medium

Incorrect implementation of QuantammMathGuard.sol#_clampWeights.

low

Inconsistent timestamp storage when the LPNFT is transferred.

Nov '24

Chiliz Chain System Contracts

Chiliz Chain System Contracts

6,306.66 USDC • Sherlock • ge6a

silver

Findings not publicly available for private contests.

Sep '24

Boost Core Incentive Protocol

Boost Core Incentive Protocol

8,348.66 USDC • 6 total findings • Sherlock • ge6a

gold

high

Revert of SignerValidator.validate() caused by bug in IncentiveBits.setOrThrow()

high

clawback() can't be executed because the owner is always BoostCore

medium

Fee on transfer tokens break some of the contracts

medium

The boost's owner can steal the protocol's profit using referralFee = 100%.

medium

block.prevdao is not secure source of randomness and could be manipulated

medium

Issue with rebasing tokens in ERC20Incentive

Aug '24

Tadle

Tadle

3.11 USDC • 4 total findings • CodeHawks • ge6a

#136

high

Incorrect set up and logic of `referralInfoMap` in `SystemConfig::updateReferrerInfo` function

high

Native token withdrawal fails until manually approved

high

`DeliveryPlace::settleAskTaker` Has Incorrect Access Control

high

Formulaic Error Rounds Down Causing Total Loss Of Funds For Bid Takers During Abort

Jul '24

ArkProject: NFT Bridge

ArkProject: NFT Bridge

63.65 USDC • 2 total findings • CodeHawks • ge6a

#38

high

`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`

medium

Starknet tokens deposited with use_withdraw_auto can never be withdrawn

MakerDAO Endgame

MakerDAO Endgame

3,422.49 USDC • Sherlock • ge6a

#29

CCIP v1.5

CCIP v1.5

1,265.29 USDC • CodeHawks • ge6a

#9

Jun '24

dHEDGE

dHEDGE

271.16 USDC • Sherlock • ge6a

#12

Findings not publicly available for private contests.

May '24

Sablier

Sablier

6,081.99 USDC • 3 total findings • CodeHawks • ge6a

silver

medium

Insufficient input validation on `SablierV2NFTDescriptor::safeAssetSymbol` allows an attacker to obtain stored XSS

medium

`SablierV2Lockup.sol` - The caller of withdraw and renounce can skip callbacks, by sending less gas

low

Cancelling a Merkle Lockup is only callable by `initialAdmin` even after `admin` had been modified

Apr '24

FairSide Network

FairSide Network

3,087.65 USDC • Sherlock • ge6a

#4

Findings not publicly available for private contests.

Alchemix - Optimism Bridging and Reward Routing

Alchemix - Optimism Bridging and Reward Routing

2,125 USDC • 1 total finding • Sherlock • ge6a

gold

high

Maximum allowable slippage can be exceeded

Beanstalk Part 2

Beanstalk Part 2

35.74 USDC • 1 total finding • CodeHawks • ge6a

#11

low

Missing the `lookback` parameter when invoking the `getWstethUsdPrice()` in the `getTokenPrice` function

Mar '24

RadicalxChange

RadicalxChange

1.18 USDC • 1 total finding • Sherlock • ge6a

bronze

high

_cancelAllBids does not check if the current bidder is the highest bid bidder

Feb '24

Perpetual

Perpetual

5,411.49 USDC • 2 total findings • Sherlock • ge6a

#6

high

Draining maker through funding fee

medium

Loss of funds for trader because whitelisted maker can't be liquidated

Smilee Finance

Smilee Finance

378.73 USDC • 2 total findings • Sherlock • ge6a

#6

medium

Permanent Dos through trackVaultFee()

medium

Manipulation of _state.liquidity.totalDeposit

Jan '24

Arcadia

Arcadia

36.24 USDC • 1 total finding • Sherlock • ge6a

#8

medium

DOS of StakedStargateAM

Flat Money

Flat Money

234.48 USDC • 2 total findings • Sherlock • ge6a

#15

medium

DOS for long periods of time due to revert in getPrice()

medium

skewFractionMax can be significantly exceeded, putting LPs at risk

SYMM IO

SYMM IO

314.01 USDC • Sherlock • ge6a

#7

Ubiquity

Ubiquity

1,866.60 USDC • 1 total finding • Sherlock • ge6a

#6

medium

Protocol insolvency and the user's inability to redeem their tokens

Dec '23

Olympus RBS 2.0

Olympus RBS 2.0

2,971.63 USDC • 3 total findings • Sherlock • ge6a

#6

high

Wrong methodology for stable BPT price calculation

high

getBunniTokenPrice wrongly returns the total price of all tokens

medium

Using incorrect function to determine the token supply in a Balancer weighted pool

Nov '23

Nouns Builder

Nouns Builder

21.94 USDC • 1 total finding • Sherlock • ge6a

#9

high

If reservedUntilTokenId > 100, the first founder will receive fewer tokens than expected

Kelp DAO | rsETH

Kelp DAO | rsETH

143.01 USDC • 1 total finding • Code4rena • ge6a

#27

medium

Lack of slippage control on LRTDepositPool.depositAsset

Oct '23

LooksRare

LooksRare

246.50 USDC • 1 total finding • Sherlock • ge6a

#7

medium

fulfillRandomWords() could revert under certain circumstances

Ethena Labs

Ethena Labs

123.66 USDC • 1 total finding • Code4rena • ge6a

#26

medium

``FULL_RESTRICTED`` Stakers can bypass restriction through approvals

Badger eBTC Audit + Certora Formal Verification Competition

Badger eBTC Audit + Certora Formal Verification Competition

117.51 USDC • Code4rena • ge6a

#15

Open Dollar

Open Dollar

22 USDC • 1 total finding • Code4rena • ge6a

#52

medium

`ODSafeManager#allowSAFE()` cannot be executed either by the proxy contract or any other address.

Sep '23

Venus Prime

Venus Prime

4.37 USDC • Code4rena • ge6a

#39

Aug '23

Dopex

Dopex

0.01 USDC • 1 total finding • Code4rena • ge6a

#129

high

The settle feature will be broken if attacker arbitrarily transfer collateral tokens to the PerpetualAtlanticVaultLP