https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/542fdf5e-4ace-41b7-9e16-6edc14a95b24.jpg

harry

Security Researcher

High

10

Total

Medium

10

Total

$7.78K

Total Earnings

#744 All Time

16x

Payouts

regular

5x

Top 10

regular

8x

Top 25

regular

11x

Top 50

All

Sherlock

Code4rena

Cantina

Nov '25

Brix Money

Brix Money

1,049.86 USDC • 1 total finding • Code4rena • harry

#4

medium

User can bypass staking restrictions through composer and deposit on another chain

Megapot

Megapot

355.98 USDC • 1 total finding • Code4rena • harry

#8

high

Unoptimized subset matches counting implementation will exceed tx gas limit on base chain

Oct '25

Centrifuge Protocol V3.1

Centrifuge Protocol V3.1

3,452.81 USDC • 1 total finding • Sherlock • harry

#7

medium

`SimplePriceManager.onUpdate()` lack of forward execution fee leads dependent functions to revert

Hybra Finance

Hybra Finance

1,212.5 USDC • 2 total findings • Code4rena • harry

#7

high

Assets deposited before calculating shares amount to mint will cause users to mint less shares.

medium

Claiming rewards in GovernanceHYBR will always revert

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

232.28 OP • 2 total findings • Sherlock • harry

#17

high

Attacker can front-run liquidity transactions to cause gauge DCA rewards to be lost

high

Gauge emissions per token not per pool allow malicious pools to capture unearned rewards

Rezerve Money

Rezerve Money

18.97 USDC • Sherlock • harry

#75

Findings not publicly available for private contests.

Aug '25

kuru-contracts

kuru-contracts

1,258.42 USDC • 1 total finding • Cantina • harry

#17

high

Finding not yet public.

GTE Perps and Launchpad

GTE Perps and Launchpad

94.17 USDC • 2 total findings • Code4rena • harry

#68

high

Risk of Gas DoS due to Looping

medium

Rounding down in Quote calculation allows underpriced LaunchToken purchases by Malicious user, compounding protocol loss over multiple buys.

Jul '25

Malda

Malda

10.64 USDC • 2 total findings • Sherlock • harry

#44

medium

`wrapAndSupplyOnExtensionMarket` fails due to missing gas fee forwarding

medium

`Rebalancer.sendMsg` uses stale transfer size causing persistent DoS

DeBank

DeBank

9.22 USDC • Sherlock • harry

#78

Notional Exponent

Notional Exponent

11.98 USDC • 1 total finding • Sherlock • harry

#49

medium

USDT approval revert leads to position entry failure

Jun '25

Symbiotic Relay

Symbiotic Relay

16.16 USDC • 1 total finding • Sherlock • harry

#11

medium

Malicious user can register many operators, leading to DoS in core view functions

DODO Cross-Chain DEX

DODO Cross-Chain DEX

2.74 USDC • 2 total findings • Sherlock • harry

#68

medium

Non-standard token incompatibility in `GatewaySend::depositAndCall`

medium

`GatewayTransferNative::withdraw` allows attacker to overwrite refund info using the same `externalId` leading to user fund loss

May '25

LEND

LEND

5.30 USDC • 2 total findings • Sherlock • harry

#97

high

Incorrect check in `_checkLiquidationValid` may cause healthy accounts to be liquidated

high

`CoreRouter::supply` uses a stale `exchangeRateStored` which causes internal accounting mismatches

Apr '25

Aegis.im YUSD

Aegis.im YUSD

45.94 OP • 1 total finding • Sherlock • harry

#4

high

Fee calculation logic in `approveRedeemRequest` is incorrect

Kinetiq

Kinetiq

4.38 USDC • 1 total finding • Code4rena • harry

#34

high

Users Who Queue Withdrawal Before A Slashing Event Disadvantage Users Who Queue After And Eventually Leads To Loss Of Funds For Them