https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/6c33cd88-2940-4320-b2d1-e47ca2549a56.png

haxagon

Security Researcher

Contact Me

High

5

Total

Medium

13

Total

$29.06K

Total Earnings

#321 All Time

6x

Payouts

gold

2x

1st Places

regular

5x

Top 10

regular

5x

Top 25

All

Sherlock

Sep '25

Dango DEX

Dango DEX

20,415.92 USDC • 11 total findings • Sherlock • haxagon

gold

high

Asymmetric liquidity provision to geometric pool can allow attacker to purchase at flat oracle price, irrespective of trade size.

high

Large swap can be split into multiple smaller swaps to purchase large orders from the geometric pool at flat oracle price

high

Incorrect rounding direction in geometric pool `ask_exact_amount_out` allows theft of funds

medium

Taker fees can be bypassed via asymmetric liquidity provision to a pool

medium

Multiplication of XYK reserves can overflow

medium

XYK `reflect_curve` is incorrect and decreases K over time leading to loss of funds for LP providers.

medium

LP fees are applied incorrectly in `reflect_curve` leading to underperforming AMM algorithm

medium

Zero initial liquidity can be provided which bricks pairs

medium

Liquidity provision is vulnerable to slippage attacks

medium

Force cancellation can be forced to fail by smart contracts that do not implement a receive() function

medium

Unbounded spam limit asks can be created to DOS force cancellation

Sep '24

Thanos L2 Native Token Bridge

Thanos L2 Native Token Bridge

4,500 USDC • 1 total finding • Sherlock • haxagon

gold

high

Address aliasing will not be applied if a contract calls `approveAndCall` directly on the portal allowing for impersonation attacks on L2

Boost Core Incentive Protocol

Boost Core Incentive Protocol

454.17 USDC • 4 total findings • Sherlock • haxagon

#8

high

Missing functionality to clawback the incentives

medium

FoT tokens will not work with budget

medium

Rebasing tokens will be stuck in the ERC20 Incentive on negative rebase

medium

Weak randomness in drawing raffle

Jul '24

MakerDAO Endgame

MakerDAO Endgame

964.34 USDC • Sherlock • haxatron

#59

Mar '24

Optimism Fault Proofs

Optimism Fault Proofs

2,203.02 USDC • 1 total finding • Sherlock • haxatron

#6

medium

Anchor state registry can be corrupted which will prevent game creation of the same type.

Jan '24

Olympus On-Chain Governance

Olympus On-Chain Governance

524.45 USDC • 1 total finding • Sherlock • haxatron

#6

medium

High risk quorum bypass by appending extra bytes into the calldata.