Banner
https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/c0f761a1-6788-495e-a3f4-3b6f11548fb9.jpg

jokr

Team of two Security Researchers

@jokrsec @0xVijayReddy .

Contact Me

High

1

Solo

31

Total

Medium

4

Solo

15

Total

$93.81K

Total Earnings

#102 All Time

8x

Payouts

gold

3x

1st Places

silver

1x

2nd Places

regular

7x

Top 10

All

Sherlock

Code4rena

CodeHawks

Aug '25

Mangrove - Vault V2 + Compound August 6th

Mangrove - Vault V2 + Compound August 6th

Collaborative Audit • Sherlock • jokr

Jul '25

MetaLend - July 31st

MetaLend - July 31st

Collaborative Audit • Sherlock • jokr

Jun '25

MetaLend - June 24th

MetaLend - June 24th

Collaborative Audit • Sherlock • jokr

May '25

LEND

LEND

10,918.76 USDC • 25 total findings • Sherlock • jokr

gold

high

The `userBorrowedAssets` array is incorrectly updated during borrow repayments.

high

`seizeTokens` are calculated with incorrect exchange rate during cross-chain liquidations.

high

Accrued rewards not reset to zero after claim

high

supply and redeem functions are using outdated exchangeRate.

high

Wrong amount of borrow will be repaid by liquidator during cross-chain liquidation

high

Incorrect ltoken address used in cross-chain liquidation success message causes liquidation failure

high

During cross-chain borrow repayments/liqudations same-chain borrows are accidentally being cleared

high

cross-chain borrows are stored with reversed srcEid and destEid, causing them to be ignored in debt calculations

high

A malicious user can withdraw his collateral in between a cross-chain borrow.

high

cross-chain liquidators can steal funds without actually repaying debt

high

No way to withdraw protocol rewards for the admin

high

Incorrect LEND reward accounting.

high

Incorrect borrow accounting due to missing interest accrual on cross-chain borrows

high

Incorrect cross-chain collateral lookup in liquidation success handler causes revert

high

Healthy positions will be liquidated due to wrong liquidation check

high

Cross-chain liquidations will be blocked due to incorrect maxLiquidatable amount calculation.

high

Invariant in borrowWithInterest can be violated causing DoS

high

Interest for cross-chain borrow is calculated with wrong index.

high

Incorrect LEND reward distribution for cross-chain borrows

high

Incorrect liquidity check during cross-chain borrows leads to bad debt

high

CoreRouter must use a lower LTV than Compound to prevent liquidations and accounting failure

medium

Borrower will loose funds if their repay transaction executes after cross-chain liquidation call

medium

Incorrect borrow amount calculation leads false liquidations.

medium

Incorrect calculations of allowed liquidatable amount

medium

Incorrect liquidity check on destination chain.

MetaLend - May 19th 2025

MetaLend - May 19th 2025

Collaborative Audit • Sherlock • jokr

Index.Fun Beta Smart Contract Security Audit – Q2 2025

Index.Fun Beta Smart Contract Security Audit – Q2 2025

Collaborative Audit • Sherlock • jokr

Feb '25

MetaLend Ronin Lending Protocol

MetaLend Ronin Lending Protocol

Collaborative Audit • Sherlock • jokr

Dec '24

Numa

Numa

41,643.87 USDC • 6 total findings • Sherlock • jokr

gold

high

An attacker can drain NumaVault right after deployment

high

cLST market can be drained using a fake collateral token address in leverageStrategy function

medium

leverageStrategy will revert due users interest rate accrual

medium

Precision loss in setMaxSpotOffsetBps function leads to Incorrect Numa Prices

medium

No slippage check for leverageStrategy function

medium

Numa tokens fee on transfer can be bypassed

Oct '24

Avantis v1.5: Cross-Asset Leverage

Avantis v1.5: Cross-Asset Leverage

8,377.43 OP • Sherlock • jokr

silver

Findings not publicly available for private contests.

Jul '24

ArkProject: NFT Bridge

ArkProject: NFT Bridge

1,987.35 USDC • 7 total findings • CodeHawks • jokrsec

#6

high

`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`

high

The Bridging Process will revert if the Collection is matched on the destination chain and not matched on the source chain

high

Infinite loop breaks whitelist removal funtionality on L2

high

`Bridge` is unable to transfer ownership and upgrade on `ERC721Bridgeable`

medium

Starknet tokens deposited with use_withdraw_auto can never be withdrawn

medium

Tokens irrecoverable by owner on L1 if not an `ERC721` receiver

low

Upon the transfer of an escrowed NFT from the bridge to the user on StarkNet, the escrow status remains unaltered, failing to be reset

Deepr

Deepr

18,894.00 USDC • Sherlock • jokr

gold

Findings not publicly available for private contests.

Apr '24

Renzo

Renzo

452.72 USDC • 6 total findings • Code4rena • jokr

#23

high

The amount of `xezETH` in circulation will not represent the amount of `ezETH` tokens 1:1

high

Withdrawals logic allows MEV exploits of TVL changes and zero-slippage zero-fee swaps

high

Incorrect calculation of queued withdrawals can deflate TVL and increase ezETH mint rate

medium

stETH/ETH Feed being used opens up to 2 way deposit<->withdrawal arbitrage

medium

Deposits will always revert if the amount being deposited is less than the bufferToFill value

medium

Lack of slippage and deadline during withdraw and deposit

Feb '24

Jala Swap

Jala Swap

363.37 USDC • 1 total finding • Sherlock • jokr

#5

medium

Permit is supported by `JalaRouter02` not implemented in `JalaERC20`

Perpetual

Perpetual

11,168.04 USDC • 2 total findings • Sherlock • jokr

#4

high

Instant arbitrage oppurtunity in OracleMaker

medium

Incorrect premium calculation in OracleMaker

Dec '23

Tally

Tally

Collaborative Audit • Sherlock • jokr