https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/940146dd-7f64-4798-b9a4-20989794ece3.jpg

molaratai

Security Researcher

Learning about smart contract auditing

High

5

Total

Medium

7

Total

$1.42K

Total Earnings

#1253 All Time

8x

Payouts

regular

3x

Top 10

regular

3x

Top 25

regular

6x

Top 50

All

Sherlock

Cantina

Aug '25

USG - Tangent

USG - Tangent

1,112.28 USDC • 2 total findings • Sherlock • molaratai

#7

medium

Delayed Reward Cut Parameter Updates (Two-Cycle Enforcement Lag)

medium

USDT Compatibility Issues in `swapTokenForPT` Function

Jul '25

Malda

Malda

10.43 USDC • 1 total finding • Sherlock • molaratai

#45

medium

`wrapAndSupplyOnExtensionMarket()` wraps entire `msg.value`, leaving no ETH for required gasFee in `supplyOnHost()`

DeBank

DeBank

87.96 USDC • Sherlock • molaratai

#33

Notional Exponent

Notional Exponent

20.91 USDC • 1 total finding • Sherlock • molaratai

#47

medium

Lack of minimum debt threshold enables unliquidatable small positions

Jun '25

Superfluid Locker System

Superfluid Locker System

127.37 USDC • 1 total finding • Sherlock • molaratai

#9

high

Double-Counting of Locked Tokens Allows Dual Reward Exploit via Staking and Liquidity

May '25

LEND

LEND

18.28 USDC • 5 total findings • Sherlock • molaratai

#72

high

Stale Exchange Rate Used for `redeem` token calculation

high

Inaccurate User Accounting Due to Stale Exchange Rate in `supply()` Function

medium

Stale Interest Accrual Leads to Underestimated Max Liquidation Amount Causing Valid Liquidations to Fail

medium

Usage of IERC20 methods would fail on some tokens due to lack of return of boolean value

medium

Potential DoS in `repayCrossChainBorrow()` and `liquidateCrossChain()`

Apr '25

Aegis.im YUSD

Aegis.im YUSD

45.94 OP • 1 total finding • Sherlock • molaratai

#4

high

Inconsistent Fee Application in `approveRedeemRequest()` Causes Collateral Imbalance

mighty-contracts

mighty-contracts

0.15 USDC • 1 total finding • Cantina • molaratai

#100

high

Finding not yet public.