https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/ef3eb2a1-5af6-441e-9dac-f796f89a23e5.jpg

heavyw8t

Security Researcher

Contact Me

High

7

Total

Medium

8

Total

$10.75K

Total Earnings

#595 All Time

5x

Payouts

silver

1x

2nd Places

regular

1x

Top 10

regular

4x

Top 25

All

Sherlock

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

60.68 OP • 5 total findings • Sherlock • heavyw8t

#20

high

Pending bucket rewards can be reset to 0 via stake/unstake every block (lastRewardIndex reset without checkpoint)

high

Cashback rewards can be claimed retroactively before program deployment leading to a loss of yield/funds

medium

Inflated emissions can be captured by staker after idle periods

medium

Retroactive mint rate increase mints past emissions at new rate

medium

Loss of yield trough severely reduced USDC cashback payouts on BNB

Dango DEX

Dango DEX

10,243.54 USDC • 5 total findings • Sherlock • heavyw8t

silver

high

Geometric pool swap costs can be evaded through repeated small transactions leading to a loss of yield for LP's

high

Geometric exact amount out floors input via into_int(), allowing an attacker to completely drain any geometric pool

medium

DOS in XYK pool liquidity provision trough one sided initial deposit

medium

Any change in bucket size will DOS order cancellation leading to frozen user funds and halts the entire auction

medium

Integer overflow in XYK invariant computation causes denial of service for high-decimal tokens

Aug '25

USG - Tangent

USG - Tangent

12.04 USDC • 2 total findings • Sherlock • heavyw8t

#59

medium

Unsafe ERC20 leftover forwarding to mutable fee treasury

medium

Zero-supply windfall condition in RewardAccumulator

Jul '25

Notional Exponent

Notional Exponent

279.58 USDC • 1 total finding • Sherlock • heavyw8t

#22

high

DOS in DineroWithdrawRequestManager can block withdrawals

May '25

LEND

LEND

157.56 USDC • 2 total findings • Sherlock • heavyw8t

#23

high

Different Token Decimals on different chains are not accounted for when borrowing or repaying across chains, leading to a loss of funds for the protocol and users

high

Incorrect if clause in LendStorage::borrowWithInterest leads to cross chain borrows not being added to the borrowed amount which breaks the liquidation and LEND distribution system