https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_3.png

hl_

Security Researcher

Contact Me

High

6

Total

Medium

12

Total

$1.14K

Total Earnings

#1203 All Time

13x

Payouts

regular

1x

Top 10

regular

3x

Top 25

regular

8x

Top 50

All

Sherlock

Code4rena

Mar '25

Nudge.xyz

Nudge.xyz

0.06 USDC • 1 total finding • Code4rena • hl_

#8

medium

Unauthorized Reallocation in `NudgeCampaign::handleReallocation` and Reward Disruption Vulnerability in `NudgeCampaign::invalidateParticipations`

Jul '24

TraitForge

TraitForge

3.28 USDC • 4 total findings • Code4rena • hl_

#75

high

The maximum number of generations is infinite

medium

There is no slippage check in the `nuke()` function.

medium

Pause and unpause functions are inaccessible

medium

NFTs mature too slowly under default settings.

Velocimeter

Velocimeter

51.43 USDC • 3 total findings • Sherlock • hl_

#48

high

Claimable gauge distributions are bricked when `killGaugeTotally` is called

high

DOS attack by delegating tokens with `MAX_DELEGATES = 1024`

medium

First liquidity provider of a stable pair can exploit the pool

Jun '23

Lybra Finance

Lybra Finance

73.06 USDC • 2 total findings • Code4rena • hl_

#64

medium

Incorrect function call in LybraRETHVault's getAssetPrice

medium

Understatement of `poolTotalPeUSDCirculation` amounts due to incorrect accounting after function `_repay` is called

Mar '23

Asymmetry contest

Asymmetry contest

50.33 USDC • 1 total finding • Code4rena • hl_

#77

medium

DoS due to external call failure

Wenwin contest

Wenwin contest

318.44 USDC • 1 total finding • Code4rena • hl_

#16

medium

The buyer of the ticket could be front-runned by the ticket owner who claims the rewards before the ticket's NFT is traded

Feb '23

Ethos Reserve contest

Ethos Reserve contest

42.07 USDC • Code4rena • hl_

#34

Blueberry

Blueberry

14.61 USDC • 1 total finding • Sherlock • hl_

#35

medium

Chainlink's latestRoundData may return stale or incorrect results

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

140.9 USDC • 2 total findings • Code4rena • hl_

#31

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`

medium

Funds can be stuck due to wrong order of operations

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

36.5 USDC • Code4rena • hl_

#55

UXD Protocol

UXD Protocol

332.26 USDC • 2 total findings • Sherlock • hl_

#17

high

Possible attacks on users for fees paid

medium

getDebtValue function not used

Nov '22

Redacted Cartel contest

Redacted Cartel contest

25.32 USDC • 1 total finding • Code4rena • hl_

#50

high

Underlying assets stealing in `AutoPxGmx` and `AutoPxGlp` via share price manipulation

LSD Network - Stakehouse contest

LSD Network - Stakehouse contest

52.03 USDC • Code4rena • hl_

#52