https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

jayjoshix

Security Researcher

Contact Me

High

6

Total

Medium

10

Total

$1.61K

Total Earnings

#1215 All Time

5x

Payouts

regular

2x

Top 10

regular

2x

Top 25

regular

4x

Top 50

All

Sherlock

Cantina

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

292.97 OP • 6 total findings • Sherlock • jayjoshix

#4

high

Attacker can zero out pending staking rewards through minimal stake manipulation

high

Multiple Pools Drain Staking Rewards via Missing Canonical Pool Enforcement

high

Per-Trade Epoch Anchoring Enables 100% Cashback Overpayment via Timing Manipulation

medium

First staker after idle period captures all emissions from zero‑stake interval

medium

Retroactive Mint Rate Application Violates Global Emission Rate Integrity

medium

Hard-coded 6-Decimal Assumption Causes Catastrophic Reward Miscalculation on BNB Chain

BMX Deli Swap

BMX Deli Swap

297.49 USDC • 2 total findings • Sherlock • jayjoshix

#10

high

Incentive Front-Loading Due to Incorrect Time Reference in Reward Accrual

medium

Fee Under-Collection in Exact-Output Swaps with Fee-from-Output

Ammplify

Ammplify

38.20 USDC • 3 total findings • Sherlock • jayjoshix

#57

medium

Ineffective transferVaultBalance Function Cannot Migrate Real Vault Balances

medium

NFTManager tokenURI() Reverts Due to Incorrect Diamond Storage Access

medium

ViewWalker Cross-Assignment Bug Causes Incorrect Fee Calculations

Aug '25

USG - Tangent

USG - Tangent

374.10 USDC • 4 total findings • Sherlock • jayjoshix

#27

high

Unauthorized Access via Spoofed ControlTower Authorization

medium

WUSR Mint Function Overcredits Users Due to Misuse of ERC4626 `previewMint

medium

Missing receive() Functions Break ETH Zap Functionality

medium

Reward Backlog Accumulation Bug Allows First Stakers After Idle Periods to Steal Rewards

kuru-contracts

kuru-contracts

605.39 USDC • 1 total finding • Cantina • jayx

#31

high

Finding not yet public.