https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

hard1k

Security Researcher

Contact Me

High

9

Total

Medium

6

Total

$1.84K

Total Earnings

#1117 All Time

7x

Payouts

regular

1x

Top 10

regular

2x

Top 25

regular

5x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

Jun '25

Chainlink Rewards

Chainlink Rewards

1.42 USDC • Code4rena • ahahaHard1k

#8

May '25

LEND

LEND

40.72 USDC • 1 total finding • Sherlock • hard1k

#49

high

LEND rewards are incorrectly distributed more times than it should when repaying the cross chain borrows

Apr '25

liquidity-book-vaults

liquidity-book-vaults

32.73 USDC • 1 total finding • Cantina • hard1k

#45

medium

Finding not yet public.

Feb '25

Core Contracts

Core Contracts

211.11 usdc • 11 total findings • CodeHawks • hard1k

#99

high

Faulty Gauge Weight Update Formula: Voting Power Delta Not Considered Leading to Arithmetic Underflow and Vote Weight Inconsistency

high

Incorrect Reward Claim Logic in FeeCollector::claimRewards Causes Denial of Service

high

Attackers can get most of RAACToken rewards by withdrawing dust amount from StabilityPool multiple times

high

Ownership Parameter Mismatch in LendingPool’s Vault Withdrawal Logic

high

Attackers can double voting power and veToken amount by locking and increasing

medium

Missing StabilityPool Integration in `mintRewards` Function

medium

LendingPool deposits do not work with CurveVault due to lack of funds

medium

Using balanceOf Instead of Voting Power

medium

Incorrect Weight Scaling in `GaugeController` Leads to Inaccurate Time-Weighted Calculations

low

Unauthorized Vote Casting Vulnerability

low

Overwriting Previous Allocations in allocateFunds May Lead to Loss of Cumulative Allocation Data

Jan '25

Part 2

Part 2

210.61 usdc • 2 total findings • CodeHawks • hard1k

#37

high

Underflow when updating credit delegation will result protocol DoS

high

Incorrect Debt Check in `CreditDelegationBranch::settleVaultsDebt` Function

Dec '24

story-protocol

story-protocol

829.35 USDC • 1 total finding • Cantina • hard1k

#51

high

Finding not yet public.

Oct '24

stakeup-bloomv2

stakeup-bloomv2

511.29 USDC • 1 total finding • Cantina • hard1k

#22

medium

Finding not yet public.