Security Researcher
High
Total
Medium
Total Earnings
#744 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
Nov '25
1,049.86 USDC • 1 total finding • Code4rena • harry
#4
medium
User can bypass staking restrictions through composer and deposit on another chain
355.98 USDC • 1 total finding • Code4rena • harry
#8
high
Unoptimized subset matches counting implementation will exceed tx gas limit on base chain
Oct '25
3,452.81 USDC • 1 total finding • Sherlock • harry
#7
`SimplePriceManager.onUpdate()` lack of forward execution fee leads dependent functions to revert
1,212.5 USDC • 2 total findings • Code4rena • harry
Assets deposited before calculating shares amount to mint will cause users to mint less shares.
Claiming rewards in GovernanceHYBR will always revert
Sep '25
232.28 OP • 2 total findings • Sherlock • harry
#17
Attacker can front-run liquidity transactions to cause gauge DCA rewards to be lost
Gauge emissions per token not per pool allow malicious pools to capture unearned rewards
18.97 USDC • Sherlock • harry
#75
Findings not publicly available for private contests.
Aug '25
1,258.42 USDC • 1 total finding • Cantina • harry
94.17 USDC • 2 total findings • Code4rena • harry
#68
Risk of Gas DoS due to Looping
Rounding down in Quote calculation allows underpriced LaunchToken purchases by Malicious user, compounding protocol loss over multiple buys.
Jul '25
10.64 USDC • 2 total findings • Sherlock • harry
#44
`wrapAndSupplyOnExtensionMarket` fails due to missing gas fee forwarding
`Rebalancer.sendMsg` uses stale transfer size causing persistent DoS
9.22 USDC • Sherlock • harry
#78
11.98 USDC • 1 total finding • Sherlock • harry
#49
USDT approval revert leads to position entry failure
Jun '25
16.16 USDC • 1 total finding • Sherlock • harry
#11
Malicious user can register many operators, leading to DoS in core view functions
2.74 USDC • 2 total findings • Sherlock • harry
Non-standard token incompatibility in `GatewaySend::depositAndCall`
`GatewayTransferNative::withdraw` allows attacker to overwrite refund info using the same `externalId` leading to user fund loss
May '25
5.30 USDC • 2 total findings • Sherlock • harry
#97
Incorrect check in `_checkLiquidationValid` may cause healthy accounts to be liquidated
`CoreRouter::supply` uses a stale `exchangeRateStored` which causes internal accounting mismatches
Apr '25
45.94 OP • 1 total finding • Sherlock • harry
Fee calculation logic in `approveRedeemRequest` is incorrect
4.38 USDC • 1 total finding • Code4rena • harry
#34
Users Who Queue Withdrawal Before A Slashing Event Disadvantage Users Who Queue After And Eventually Leads To Loss Of Funds For Them