https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_0.png

holtzzx

Security Researcher

Contact Me

High

7

Total

Medium

19

Total

$8.13K

Total Earnings

#690 All Time

19x

Payouts

regular

3x

Top 10

regular

9x

Top 25

regular

16x

Top 50

All

Sherlock

Code4rena

Cantina

Oct '25

3Jane

3Jane

1,931.92 USDC • Sherlock • holtzzx

#7

Findings not publicly available for private contests.

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

5.61 OP • 1 total finding • Sherlock • holtzzx

#45

high

`collectFees` will never work when the other asset of the pool is ETH

Dango DEX

Dango DEX

540.67 USDC • 2 total findings • Sherlock • holtzzx

#17

medium

Overflow of xyk due to uint128 results

medium

There isn't slippage specified when adding liquidity

Ammplify

Ammplify

365.22 USDC • 4 total findings • Sherlock • holtzzx

#18

high

Loss of fees on the way up due to incorrect compoundingLiq

medium

Vaults won't work with tokens that revert on a 0 value approval

medium

Attacker can get `TAKER_VAULT_ID` and steal all tokens

medium

An maker can never exit fully

Aug '25

USG - Tangent

USG - Tangent

311.18 USDC • 1 total finding • Sherlock • holtzzx

#29

medium

Any zapping call with ETH as the token out will return nothing, hence functions that call it will revert with 0 amount.

Yield Basis

Yield Basis

114.27 USDC • 2 total findings • Sherlock • holtzzx

#9

medium

Inverted check for `gc` parameter in Factory::set_gauge_controller

medium

InflationaryVest::claim forgets to update `self.claimed`

solayer-bridge

solayer-bridge

120 USDC • 1 total finding • Cantina • holtzzx

#36

medium

Finding not yet public.

Jul '25

Malda

Malda

1,974.73 USDC • 1 total finding • Sherlock • holtzzx

#8

medium

Some tokens will not work for Everclear rebalancing

Mellow Flexible Vaults

Mellow Flexible Vaults

0.04 USDC • 1 total finding • Sherlock • holtzzx

#43

medium

In case of a transfer of TokenizedShareManager, the `updateChecks` function is inverted logic in the branch, will incorrectly DOS.

Notional Exponent

Notional Exponent

21.07 USDC • 2 total findings • Sherlock • holtzzx

#46

medium

Zero-Duration Cooldown in EthenaCooldownHolder Swallows Redeemed USDe

medium

StakingStrategy and CurveConvex2Token require that chainid is Mainet, but protocol says possible deployments on Arbitrum and Base

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

0.26 USDC • 1 total finding • Sherlock • holtzzx

#72

medium

`GatewaySend::depositAndCall` functions will not work with USDT

May '25

LEND

LEND

33.83 USDC • 1 total finding • Sherlock • holtzzx

#57

high

Wrong LToken address is being carried across chains causes unexpected reverts on Liquidations

Audit 507

Audit 507

115.05 USDC • Code4rena • holtzzx

#19

mystic-monorepo

mystic-monorepo

58.96 USDC • 1 total finding • Cantina • holtzzx

#47

medium

Finding not yet public.

alchemix-v3

alchemix-v3

1,336.08 USDC • 1 total finding • Cantina • holtzzx

#16

high

Finding not yet public.

Apr '25

mighty-contracts

mighty-contracts

25.39 USDC • 1 total finding • Cantina • holtzzx

#55

high

Finding not yet public.

Kinetiq

Kinetiq

349.77 USDC • 1 total finding • Code4rena • holtzzx

#18

medium

Attacker can partially DoS L1 operations in StakingManager by making huge number of deposits

infinifi-protocol

infinifi-protocol

641.63 USDC • 2 total findings • Cantina • holtzzx

#16

medium

Finding not yet public.

medium

Finding not yet public.

Feb '25

Virtuals Protocol

Virtuals Protocol

182.96 USDC • 3 total findings • Code4rena • holtzzx

#39

high

Lack of Access Control in `AgentNftV2::addValidator()` Enables Unauthorized Validator Injection and Causes Reward Accounting Inconsistencies

high

Public `ServiceNft::updateImpact` call leads to cascading issue

medium

Precision loss in priceALast, priceBLass