https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/d9d4d740-d579-4499-b0f1-7b3fd2199f28.png

m3dython

Security Researcher

| Smart Contract Auditor & Security Researcher | Sharing Audit Techniques & Vulnerabilities

Contact Me

High

8

Total

Medium

3

Total

$3.16K

Total Earnings

#933 All Time

6x

Payouts

regular

2x

Top 10

regular

3x

Top 25

regular

5x

Top 50

All

Sherlock

Jul '25

DeBank

DeBank

465.45 USDC • Sherlock • m3dython

#7

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

75.65 USDC • 1 total finding • Sherlock • m3dython

#39

medium

Any External Actor will Steal Approved ZRC20 Tokens from `GatewayTransferNative` Contract

May '25

LEND

LEND

41.26 USDC • 5 total findings • Sherlock • m3dython

#52

high

CrossChainRouter will use incorrect collateral amount and token for debt repayment during cross-chain liquidation, disrupting the process for the protocol, liquidators, and borrowers

high

Incorrect Liquidation Check in `_checkLiquidationValid` May Lead to Unfair Liquidations or Prevention of Valid Liquidations

high

Incorrect Logic in `borrowWithInterest` Leads to Understated Cross-Chain Debt and Risk of Protocol Insolvency

high

CoreRouter Prone to Fund Depletion or Trapping Due to Miscalculated Redemption Payouts

medium

Liquidator may under-liquidate positions due to `maxClose` using incompletely accrued balance for same-chain borrows

Apr '25

Burve

Burve

2,509.74 USDC • 3 total findings • Sherlock • m3dython

#8

high

Zero Tax Exploitation in Withdrawal Function

high

Contract logic flaw will mismatch internal and external vault shares, potentially trapping user funds.

high

Attacker can steal user funds via ERC4626 inflation attack on underlying vault

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

19.47 USDC • Sherlock • m3dython

#39

Feb '25

Yieldoor

Yieldoor

48.21 USDC • 2 total findings • Sherlock • m3dython

#15

high

Uninitialized feeRecipient will divert protocol fees to the zero address, impacting protocol revenue

medium

A malicious actor will exploit the miscalculation, impacting leveraged position holders