Banner
https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/7e6ffabd-9581-4a49-a9f7-761f5960db93.png

nirohgo

Security Researcher

Security Researcher. Open for private audits.

High

6

Total

Medium

4

Total

$27.47K

Total Earnings

#291 All Time

10x

Payouts

silver

2x

2nd Places

bronze

2x

3rd Places

regular

9x

Top 10

All

Sherlock

Blackthorn

Mar '25

WrappedM token V2

WrappedM token V2

Collaborative Audit • Blackthorn • nirohgo

Feb '25

Usual Stability Loan

Usual Stability Loan

Collaborative Audit • Sherlock • nirohgo

Oct '24

Usual V1

Usual V1

4,354.08 USDC • 1 total finding • Sherlock • nirohgo

silver

high

UsualSP removeOriginalAllocation does not call _updateReward before zeroing recipient balances depriving them of already earned rewards

Jul '24

MakerDAO Endgame

MakerDAO Endgame

5,937.57 USDC • Sherlock • nirohgo

#20

Jun '24

Notional Leveraged Vaults: Pendle PT and Vault Incentives

Notional Leveraged Vaults: Pendle PT and Vault Incentives

2,187.28 USDC • 4 total findings • Sherlock • nirohgo

#4

high

Reward emissions can be blocked with a DOS attack due to insufficient precision is emissions calculation

high

Precision calculation error in PendlePTOracle::_calculateBaseToQuote causing erroneous price reports

high

WithdrawRequestBase::_getValueOfSplitFinalizedWithdrawRequest does not account for decimals when converting from redeem token to borrow token

medium

VaultRewardLib decreases a user's claimable reward amount even if the reward transfer fails

Mar '24

Optimism Fault Proofs

Optimism Fault Proofs

2,203.02 USDC • 1 total finding • Sherlock • nirohgo

#6

medium

The FGD l2BlockNumber (passed in extraData) can be any number, enabling a DOS on fund widthdrawals

Seismic Finance

Seismic Finance

1,221.41 USDC • Sherlock • nirohgo

bronze

Findings not publicly available for private contests.

Feb '24

Perpetual

Perpetual

3,833.80 USDC • 1 total finding • Sherlock • nirohgo

#8

high

Funding Fee Rate is calculated based only on the Oracle Maker's skew but applied across the entire market, which enables an attacker to generate an extreme funding rate for a low cost and leverage that to their benefit

Jan '24

SYMM IO

SYMM IO

805.39 USDC • Sherlock • nirohgo

silver
Ubiquity

Ubiquity

371.99 USDC • 1 total finding • Sherlock • nirohgo

#7

medium

The TWAPOracleFacet TWAP timeframe depends on the distance from the last update() call, which compromises the price accuracy and enables price manipulation..

Dec '23

Olympus RBS 2.0

Olympus RBS 2.0

4,031.66 USDC • 1 total finding • Sherlock • nirohgo

#4

high

Price Module reports wrong MA/Current Price for asset using MA when feeds are down after storePrice has been called

Nov '23

Nouns Builder

Nouns Builder

2,525.33 USDC • 1 total finding • Sherlock • nirohgo

bronze

medium

Migrated DAO exposed to Hijacking shortly after creation due to insecure renounceOwnership function