https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

khaye26

Security Researcher

never place your private keys in .env

Contact Me

High

2

Total

Medium

7

Total

$1.69K

Total Earnings

#1191 All Time

9x

Payouts

gold

1x

1st Places

regular

2x

Top 10

regular

2x

Top 25

All

Sherlock

Cantina

Sep '25

Ammplify

Ammplify

34.34 USDC • 1 total finding • Sherlock • khaye26

#59

medium

Vault Removal Ignores Direct Token Transfers

Aug '25

USG - Tangent

USG - Tangent

5.60 USDC • 1 total finding • Sherlock • khaye26

#63

medium

transferFrom in stETH will transfer 1-2 less way, which would result in revert in consequent functions, because of not enough balance

Neutrl Protocol

Neutrl Protocol

941.02 USDC • 1 total finding • Sherlock • khaye26

gold

medium

Fully blacklisted users can stake and specify a different receiver address

Jul '25

Mellow Flexible Vaults

Mellow Flexible Vaults

163.25 USDC • 1 total finding • Sherlock • khaye26

#30

high

Improper Handling of Native ETH in `getLiquidAssets` Leads to Potential Denial of Service

DeBank

DeBank

3.63 USDC • Sherlock • khaye26

#96

Notional Exponent

Notional Exponent

134.23 USDC • 1 total finding • Sherlock • khaye26

#34

medium

Chain-Specific Interface Mismatch in Convex Deposit Function

Jun '25

solaxy

solaxy

393.52 USDC • 1 total finding • Cantina • Khaye

#8

medium

Finding not yet public.

DODO Cross-Chain DEX

DODO Cross-Chain DEX

10.81 USDC • 1 total finding • Sherlock • khaye26

#55

high

`_doMixSwap` blindly approves whatever token is specified in params.fromToken

May '25

LEND

LEND

2.53 USDC • 2 total findings • Sherlock • khaye26

#105

medium

Borrowers will pay excessive interest due to double interest calculation in `CoreRouter::borrow`

medium

Usage of IERC20 transfer method would fail on some tokens due to lack of return of boolean value