Security Researcher
High
Total
Medium
Total Earnings
#690 All Time
Payouts
Top 10
Top 25
Top 50
All
Sherlock
Code4rena
Cantina
Oct '25
1,931.92 USDC • Sherlock • holtzzx
#7
Findings not publicly available for private contests.
Sep '25
5.61 OP • 1 total finding • Sherlock • holtzzx
#45
high
`collectFees` will never work when the other asset of the pool is ETH
540.67 USDC • 2 total findings • Sherlock • holtzzx
#17
medium
Overflow of xyk due to uint128 results
There isn't slippage specified when adding liquidity
365.22 USDC • 4 total findings • Sherlock • holtzzx
#18
Loss of fees on the way up due to incorrect compoundingLiq
Vaults won't work with tokens that revert on a 0 value approval
Attacker can get `TAKER_VAULT_ID` and steal all tokens
An maker can never exit fully
Aug '25
311.18 USDC • 1 total finding • Sherlock • holtzzx
#29
Any zapping call with ETH as the token out will return nothing, hence functions that call it will revert with 0 amount.
114.27 USDC • 2 total findings • Sherlock • holtzzx
#9
Inverted check for `gc` parameter in Factory::set_gauge_controller
InflationaryVest::claim forgets to update `self.claimed`
120 USDC • 1 total finding • Cantina • holtzzx
#36
Jul '25
1,974.73 USDC • 1 total finding • Sherlock • holtzzx
#8
Some tokens will not work for Everclear rebalancing
0.04 USDC • 1 total finding • Sherlock • holtzzx
#43
In case of a transfer of TokenizedShareManager, the `updateChecks` function is inverted logic in the branch, will incorrectly DOS.
21.07 USDC • 2 total findings • Sherlock • holtzzx
#46
Zero-Duration Cooldown in EthenaCooldownHolder Swallows Redeemed USDe
StakingStrategy and CurveConvex2Token require that chainid is Mainet, but protocol says possible deployments on Arbitrum and Base
Jun '25
0.26 USDC • 1 total finding • Sherlock • holtzzx
#72
`GatewaySend::depositAndCall` functions will not work with USDT
May '25
33.83 USDC • 1 total finding • Sherlock • holtzzx
#57
Wrong LToken address is being carried across chains causes unexpected reverts on Liquidations
115.05 USDC • Code4rena • holtzzx
#19
58.96 USDC • 1 total finding • Cantina • holtzzx
#47
1,336.08 USDC • 1 total finding • Cantina • holtzzx
#16
Apr '25
25.39 USDC • 1 total finding • Cantina • holtzzx
#55
349.77 USDC • 1 total finding • Code4rena • holtzzx
Attacker can partially DoS L1 operations in StakingManager by making huge number of deposits
641.63 USDC • 2 total findings • Cantina • holtzzx
Feb '25
182.96 USDC • 3 total findings • Code4rena • holtzzx
#39
Lack of Access Control in `AgentNftV2::addValidator()` Enables Unauthorized Validator Injection and Causes Reward Accounting Inconsistencies
Public `ServiceNft::updateImpact` call leads to cascading issue
Precision loss in priceALast, priceBLass