Banner
https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/65d4558f-c313-42ce-8bf8-c4b8a0872857.jpg

gh0xt

Security Researcher

Smart Contract Auditor | Web3 Security Researcher | Fuzzing • Invariant Testing • DeFi Exploits

Contact Me

High

7

Total

Medium

1

Solo

10

Total

$33.59K

Total Earnings

#291 All Time

9x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

regular

2x

Top 10

All

Sherlock

Code4rena

Cantina

Oct '25

Centrifuge Protocol V3.1

Centrifuge Protocol V3.1

30,390.71 USDC • 2 total findings • Sherlock • gh0xt

silver

high

Malicious BRM permits global escrow drain

medium

Stranded ETH on batched `crosschainTransferShares` call

Sep '25

Ammplify

Ammplify

29.16 USDC • 2 total findings • Sherlock • gh0xt

#62

medium

`adjustMaker` blocks X sided withdrawals

medium

`collectFees()` deducts penalty for MAKER_NC

Aug '25

USG - Tangent

USG - Tangent

61.52 USDC • 3 total findings • Sherlock • gh0xt

#48

high

Market collateral drain with migrateTo()

medium

Liquidators lose value == liquidation fee at parity

medium

First depositor after a zero supply window will capture unearned rewards

kuru-contracts

kuru-contracts

1,572.03 USDC • 2 total findings • Cantina • gh0xt

#14

high

Finding not yet public.

high

Finding not yet public.

Neutrl Protocol

Neutrl Protocol

941.02 USDC • 1 total finding • Sherlock • gh0xt

gold

medium

FULL_RESTRICTED users stake bypass

Jul '25

Malda

Malda

51.85 USDC • 3 total findings • Sherlock • gh0xt

#37

medium

Blacklist Bypass in `mTokenGateway.outHere`

medium

Stale window check in `Rebalancer.sendMsg()` causes rollover-time DoS

medium

Value forwarding gap in wrapAndSupplyOnExtensionMarket can make supplyOnHost revert

GTE Spot CLOB and Router

GTE Spot CLOB and Router

16.95 USDC • 1 total finding • Code4rena • gh0xt

#21

high

Order double-linked list is broken because order.prevOrderId is not persisted

May '25

superform-core

superform-core

521.69 USDC • 2 total findings • Cantina • gh0xt

#17

high

Finding not yet public.

medium

Finding not yet public.

Apr '25

Burve

Burve

9.46 USDC • 1 total finding • Sherlock • gh0xt

#29

high

Logical Error in ValueFacet Causes Protocol-Wide Fee Bypass