https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

hack3r-0m

Security Researcher

Contact Me

High

9

Total

Medium

15

Total

$49.63K

Total Earnings

#203 All Time

19x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

8x

Top 10

All

Sherlock

Blackthorn

Code4rena

Cantina

Feb '25

Interchain Labs IBC Eureka

Interchain Labs IBC Eureka

Collaborative Audit • Sherlock • hack3r-0m

Nov '24

hyperlend

hyperlend

12,385.91 USDC • 1 total finding • Cantina • hack3r-0m

bronze

medium

Finding not yet public.

Oct '24

Ethereum Foundation

Ethereum Foundation

Collaborative Audit • Blackthorn • hack3r-0m

Jul '24

MakerDAO Endgame

MakerDAO Endgame

3,138.90 USDC • Sherlock • hack3r-0m

#31

Feb '24

eigenlayer-contracts

eigenlayer-contracts

1,500 USDC • Cantina • hack3r-0m

#4

Jul '23

Tapioca DAO

Tapioca DAO

61.03 USDC • 3 total findings • Code4rena • hack3r-0m

#82

high

Reentrancy in `USDO.flashLoan()`, enabling an attacker to borrow unlimited USDO exceeding the max borrow limit

medium

`ARBTriCryptoOracle` is vulnerable to read-only reentrancy

medium

all deposit and withdraw function in Convex and Curve nativeLP Strategy, apply slippage on internal pricing; which call real-time on chain price from Curve directly and subject to MEV

Feb '23

GMX

GMX

3,271.67 USDC • 4 total findings • Sherlock • hack3r-0m

#10

high

while creating deposit, fee can be deducted in wrong manner if initialToken is not final token

high

faulty abi decoding from revert in catch block can lead to attacker controlled execution

medium

potentially using old price from pricefeed in oracle due to unchecked timestamp difference

medium

unsatisfiable condition in `getAdjustedLongAndShortTokenAmounts`

May '22

OpenSea Seaport contest

OpenSea Seaport contest

2,474.5 USDC • Code4rena • hack3r-0m

#19

Jan '22

Yield-Convex contest

Yield-Convex contest

69.12 USDC • 1 total finding • Code4rena • hack3r-0m

#15

medium

Oracle data feed is insufficiently validated.

Trader Joe contest

Trader Joe contest

134.79 USDT • 2 total findings • Code4rena • hack3r-0m

#28

medium

Use safeTransfer/safeTransferFrom consistently instead of transfer/transferFrom

medium

ERC20 return values not checked

Sherlock contest

Sherlock contest

1,972.28 USDC • 1 total finding • Code4rena • hack3r-0m

#11

medium

tokenBalanceOfAddress of nftOwner becomes permanently incorrect after arbRestake

XDEFI contest

XDEFI contest

67.64 USDC • Code4rena • hack3r-0m

#23

Nov '21

Streaming Protocol contest

Streaming Protocol contest

11,111.38 USDC • 3 total findings • Code4rena • hack3r-0m

gold

high

Tokens can be stolen when `depositToken == rewardToken`

high

DOS while dealing with erc20 when value(i.e amount*decimals) is high but less than type(uint112).max

high

Improper implementation of `arbitraryCall()` allows protocol gov to steal funds from users' wallets

yAxis contest

yAxis contest

29.93 USDC • Code4rena • hack3r-0m

#15

Nested Finance contest

Nested Finance contest

1,249.62 USDC • 1 total finding • Code4rena • hack3r-0m

#11

medium

FeeSplitter: No sanity check to prevent shareholder from being added twice.

Vader Protocol contest

Vader Protocol contest

1,816.94 USDC • 1 total finding • Code4rena • hack3r-0m

#12

high

Unrestricted vestFor

Oct '21

BadgerDAO ibBTC Wrapper contest

BadgerDAO ibBTC Wrapper contest

1,412.24 ETH • 2 total findings • Code4rena • hack3r-0m

#8

high

WrappedIbbtcEth contract will use stalled price for mint/burn if updatePricePerShare wasn't run properly

medium

Null check in pricePerShare

Sep '21

Kuiper contest

Kuiper contest

678.39 USDC • 2 total findings • Code4rena • hack3r-0m

#15

medium

Use safeTransfer instead of transfer

medium

`burn` and `mintTo` in `Basket.sol` vulnerable to reentrancy

Sushi Trident contest phase 1

Sushi Trident contest phase 1

6,618.6 USDC • 1 total finding • Code4rena • hack3r-0m

#7

high

absolute difference is not calculated properly when a > b in MathUtils

Aug '21

Gravity Bridge contest

Gravity Bridge contest

422.79 USDC • Code4rena • hack3r-0m

#8

Float Capital contest

Float Capital contest

1,217.87 USDC • 2 total findings • Code4rena • hack3r-0m

#8

medium

Incorrect balance computed in `getUsersConfirmedButNotSettledSynthBalance()`

medium

latestMarket used where marketIndex should have been used