https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

iam0ti

Security Researcher

Breaking Software for fun and profit.

Contact Me

High

14

Total

Medium

22

Total

$2.25K

Total Earnings

#1064 All Time

9x

Payouts

bronze

1x

3rd Places

regular

2x

Top 10

regular

6x

Top 25

All

Sherlock

Cantina

CodeHawks

Jul '25

Allbridge Core Yield

Allbridge Core Yield

150.46 USDC • 1 total finding • Sherlock • iam0ti

bronze

medium

Attacker will steal funds from depositors through share inflation attack

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

519.48 USDC • 10 total findings • Sherlock • AnomX

#9

high

Unauthorized Refund Claims for Non-EVM Addresses

high

Attacker can steal an high-value token due to lack of swap execution

high

An attacker will steal protocol funds from reverted cross-chain txs

medium

Incorrect Swap Amount After Fee Deduction

medium

ETH Revert Handling Failure in Cross-Chain Operations

medium

ETH Address Approval Attempt Causes All Zeta Swaps to Revert

medium

Platform Fee Bypass in Zeta Swap Execution

medium

An attacker will cause transaction reverts for users by spoofing Uniswap V2 pool existence

medium

Untrusted `onAbort`/`onRevert` call will allow overwriting of legitimate external ID for cross-chain refund logic

medium

Bitcoin Address Truncation in Revert Message Causes Failed Refunds

May '25

stability-contracts

stability-contracts

257.8 USDC • 3 total findings • Cantina • AnomX-StabilityDAO

#13

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

mystic-monorepo

mystic-monorepo

44.64 USDC • 2 total findings • Cantina • IAM0TI

#50

medium

Finding not yet public.

medium

Finding not yet public.

Apr '25

mighty-contracts

mighty-contracts

153 USDC • 6 total findings • Cantina • IAM0TI

#25

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

mezo-monorepo

mezo-monorepo

659.8 USDC • 1 total finding • Cantina • IAM0TI

#20

high

Finding not yet public.

Mar '25

colorpool-chromia

colorpool-chromia

302.5 USDC • 2 total findings • Cantina • IAM0TI

#20

high

Finding not yet public.

medium

Finding not yet public.

Feb '25

velvet-v4

velvet-v4

64.47 USDC • 1 total finding • Cantina • IAM0TI

#30

medium

Finding not yet public.

Core Contracts

Core Contracts

97.68 usdc • 11 total findings • CodeHawks • anomX

#145

high

RAACNFT mint function receives funds to address(this) but has no way of withdrawing them

high

Reward manipulation vulnerability in StabilityPool

high

RToken's transfer function lead to loss of funds due to incorrect math

high

NFTs Get Permanently Locked in Stability Pool After Liquidation

medium

Incorrect utilization rate forces protocol to issue maximum rewards indefinitely

medium

Incorrect DebtToken totalSupply Scaling Breaks Interest Rate Calculations

medium

Users Can Lose Funds and Collateral by Repaying Loans After Liquidation Grace Period Expiry

medium

`RToken::calculateDustAmount` are incorrectly calculated, leading to not be able to transfer the accrued dust amount

medium

getNormalizedDebt will return a wrong Amount when Timedelta is 0.

medium

`ReserveLibrary.getNormalizedDebt` doesn't return normalized debt

low

Incorrect Timestamp Tracking in RAACHousePrice contract