https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

kom

Security Researcher

Contact Me

High

14

Total

Medium

13

Total

$722.00

Total Earnings

#1400 All Time

11x

Payouts

regular

4x

Top 25

regular

7x

Top 50

All

Sherlock

Code4rena

Cantina

CodeHawks

May '25

LEND

LEND

15.05 USDC • 4 total findings • Sherlock • kom

#76

high

Missing Interest Accrual When Updating Cross‐Chain Borrow Principal

medium

Use of transfer Instead of OpenZeppelin’s safeTransfer for ERC-20 Transfers

medium

Double Counting Interest in Collateral Check Due to Redundant Index Scaling

medium

Missing addUserSuppliedAsset Call for Liquidator After Seizing Collateral

superform-core

superform-core

282.16 USDC • 2 total findings • Cantina • komkh

#19

medium

Finding not yet public.

medium

Finding not yet public.

alchemix-v3

alchemix-v3

0.04 USDC • 3 total findings • Cantina • komkh

#121

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

Apr '25

Burve

Burve

67.10 USDC • 2 total findings • Sherlock • kom

#25

high

Incorrect Tax Calculation in removeValueSingle leads to no tax

medium

Missing selectors from `BaseAdminFacet` for diamond cuts

Kinetiq

Kinetiq

21.68 USDC • 2 total findings • Code4rena • komronkh

#30

high

Users Who Queue Withdrawal Before A Slashing Event Disadvantage Users Who Queue After And Eventually Leads To Loss Of Funds For Them

medium

Incorrect Balance Check in Validator Redelegation Process May Block Legitimate Rebalancing Operations

Mar '25

Forte: Float128 Solidity Library

Forte: Float128 Solidity Library

4.03 USDC • 1 total finding • Code4rena • komronkh

#28

high

Natural Logarithm Function Silently Accepts Invalid Non-Positive Inputs

badger-ebtc-bsm

badger-ebtc-bsm

14.85 USDC • 1 total finding • Cantina • komkh

#31

high

Finding not yet public.

Feb '25

Yieldoor

Yieldoor

48.11 USDC • 1 total finding • Sherlock • kom

#16

high

feeRecipient Address not initiated or set in Leverager.sol

Core Contracts

Core Contracts

25.18 usdc • 10 total findings • CodeHawks • kkk

#232

high

`GaugeController` does not send funds to FeeCollector disrupting fees distribution and causing loss of funds

high

Incorrect Reward Claim Logic in FeeCollector::claimRewards Causes Denial of Service

high

Boost Miscalculation Leads to Excess Distribution

high

Attackers can double voting power and veToken amount by locking and increasing

medium

Liquidation Cannot Be Closed Even With Healthy Position Due To Strict Debt Check

medium

Using balanceOf Instead of Voting Power

medium

There is no logic checking for RAACNFT price staleness before minting it

medium

Flawed Boost Multiplier Calculation Always Yields Maximum Boost

medium

Inconsistent Fee Collector Address Validation in RAACMinter: Denial of Service for Disabling Fee Collection

low

`DebtToken::burn`'s Return Values are wrong

Jan '25

IQ AI

IQ AI

243.25 USDC • 1 total finding • Code4rena • komronkh

#13

high

Adversary can win proposals with voting power as low as 4%

Dec '24

QuantAMM

QuantAMM

0.82 op • 1 total finding • CodeHawks • kkk

#78

medium

quantAMMSwapFeeTake used for both getQuantAMMSwapFeeTake and getQuantAMMUpliftFeeTake.