https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/0a275040-d3cd-4b96-8a73-bd93347cb6ef.png

heeze

Security Researcher

Grinding my way to the top 💪💪

Contact Me

High

17

Total

Medium

10

Total

$3.97K

Total Earnings

#812 All Time

14x

Payouts

bronze

3x

3rd Places

regular

6x

Top 10

regular

10x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Apr '25

Burve

Burve

304.89 USDC • 3 total findings • Sherlock • heeze

#20

high

Double taxation in removeValueSingle due to incorrect tax application sequence

high

Zero fee calculation due to uninitialized removedBalance variable in removeValueSingle

medium

Missing owner acceptance function will prevent ownership transfer completion

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

62.25 USDC • Sherlock • heeze

#22

Feb '25

THORWallet

THORWallet

346.49 USDC • 1 total finding • Code4rena • hezze

bronze

high

The user can send tokens to any address by using two bridge transfers, even when transfers are restricted.

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • heeze

bronze

medium

Arithmetic operation on the userTokenAmount and refundCurrencyAmount/additionalCurrencyAmount is incorrect

Jan '25

reserve-index-dtf

reserve-index-dtf

53.43 USDC • 1 total finding • Cantina • heeze

#8

medium

Finding not yet public.

Aave v3.3

Aave v3.3

615.24 USDC • Sherlock • heeze

#38

Dec '24

Alchemix Transmuter

Alchemix Transmuter

782.99 op • 4 total findings • CodeHawks • _frolic

bronze

medium

Incorrect Total Assets Calculation in _harvestAndReport Leading to Share Value Manipulation and Irredeemable Assets

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

medium

Inflated `totalAssets` in `StrategyMainnet`, `StrategyArb`, and `StrategyOp` Contracts

low

Old router retains token allowance after update

InterPol

InterPol

156.87 USDC • 1 total finding • Cantina • heeze

#10

high

Finding not yet public.

Oct '24

Ethos Network Social Contracts

Ethos Network Social Contracts

45.37 USDC • 1 total finding • Sherlock • heeze

#6

medium

Removed account still has access to the profile, as `EthosProfile::profileIdByAddress` mapping is not deleted when deleting an account.

stakeup-bloomv2

stakeup-bloomv2

555.29 USDC • 3 total findings • Cantina • heeze

#20

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Sep '24

symbioticfi-core

symbioticfi-core

348.46 USDC • 1 total finding • Cantina • heeze

#11

medium

Finding not yet public.

Flayer

Flayer

489.38 USDC • 3 total findings • Sherlock • heeze

#30

high

Contract cannot receive native token

high

Royalties paid on L2 for ERC1155 tokens cannot be claimed

high

Incorrect index of checkpoint

Aug '24

Tadle

Tadle

204.33 USDC • 9 total findings • CodeHawks • _frolic

#29

high

TokenManager - Unlimited withdraw

high

Taker of bid offer will loss assets without any benefit if he calls the DeliveryPlace::settleAskMaker() for partial settlement.

high

Native token withdrawal fails until manually approved

high

`DeliveryPlace::settleAskTaker` Has Incorrect Access Control

high

Formulaic Error Rounds Down Causing Total Loss Of Funds For Bid Takers During Abort

high

The `DeliveryPlace::settleAskTaker()` function mistakenly uses `makerInfo.tokenAddress` to update the `TokenBalanceType.PointToken` in the `userTokenBalanceMap` mapping, leading to a critical error.

high

Fund Withdrawal Flaw in preMarket Allows Users to Avoid Settlement Obligations

low

`listOffer` Unsafely References Fungible Identifiers

low

3 `OfferStatus` are never used, and code seems to have contradicting intentions

Jun '24

Size

Size

3.48 USDC • 2 total findings • Code4rena • hezze

#60

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

medium

Multicall does not work as intended