https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/32c8bba7-7bd6-48b7-a5e6-04184257c4c3.PNG

sabanaku77

Web3 Researcher

Contact Me

High

13

Total

Medium

8

Total

$3.44K

Total Earnings

#912 All Time

8x

Payouts

silver

2x

2nd Places

regular

4x

Top 10

regular

6x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

May '25

stability-contracts

stability-contracts

1,784.24 USDC • 3 total findings • Cantina • sabanaku

silver

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

mystic-monorepo

mystic-monorepo

67 USDC • 3 total findings • Cantina • sabanaku

#38

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Apr '25

mighty-contracts

mighty-contracts

69.41 USDC • 6 total findings • Cantina • sabanaku

#35

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

Mar '25

Crestal Network

Crestal Network

921.20 USDC • 4 total findings • Sherlock • sabanaku77

silver

high

Anyone can drain funds by calling payWithERC20() in Payment.sol

medium

Signature Replay attack possible on `updateWorkerDeploymentConfigWithSig()` in Blueprintcore.sol which leads to users lose the funds

medium

Unconditional Overwrite in `setWorkerPublicKey` in BlueprintCore.sol which results users to lose funds

medium

Lack of access control in `setWorkerPublicKey()` in BlueprintCore.sol which results users to lose funds

Storage Proofs

Storage Proofs

275.47 op • 1 total finding • CodeHawks • sabanaku77

#5

low

Asymmetric price constraints allow way larger upside movement invalidating security measure of limitting this

Jan '25

Next Generation

Next Generation

3.65 USDC • 1 total finding • Code4rena • sabanaku77

#14

high

Cross-Chain Signature Replay Attack Due to User-Supplied `domainSeparator` and Missing Deadline Check

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • sabanaku77

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

daao-contracts

daao-contracts

316.8 USDC • 3 total findings • Cantina • sabanaku

#10

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.