https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_7.png

skipper

Security Researcher

Contact Me

High

6

Total

Medium

7

Total

$1.97K

Total Earnings

#1203 All Time

9x

Payouts

bronze

1x

3rd Places

regular

1x

Top 10

regular

3x

Top 25

All

Sherlock

Cantina

CodeHawks

Immunefi

Nov '25

stNXM by EaseDeFi

stNXM by EaseDeFi

1.02 USDC • 2 total findings • Sherlock • kowolski

#45

high

`stNXM.sol` uses `sqrtPriceX96` when calculating `dexBalances()` which is manipulatable

medium

Lack of slippage protection when decreasing liquidity

Oct '25

Audit Comp | Belong

Audit Comp | Belong

1,883 USDC • 1 total finding • Immunefi • ZestfulHedgehog609

bronze

high

Finding not yet public.

Jun '25

DODO Cross-Chain DEX

DODO Cross-Chain DEX

0.47 USDC • 2 total findings • Sherlock • skipper

#71

high

Anyone can claim refund and steal tokens

medium

Use of `transfer()` instead of `safeTransfer()` can cause certain Transactions to fail.

May '25

LEND

LEND

2.46 USDC • 1 total finding • Sherlock • skipper

#106

medium

use of `transfer()` instead of `safeTransfer()` causes certain token transfer to fail.

mystic-monorepo

mystic-monorepo

7.27 USDC • 2 total findings • Cantina • skipper

#67

high

Finding not yet public.

medium

Finding not yet public.

Apr '25

mighty-contracts

mighty-contracts

0.15 USDC • 1 total finding • Cantina • skipper

#100

high

Finding not yet public.

Audit Comp | Spectra Finance

Audit Comp | Spectra Finance

77 USDC • 2 total findings • Immunefi • ZestfulHedgehog609

#11

medium

Finding not yet public.

medium

Finding not yet public.

Mar '25

Crestal Network

Crestal Network

0.01 USDC • 1 total finding • Sherlock • skipper

#12

high

[H-1] Arbitrary `from` passed to `transferFrom` in `Payment.sol::payWithERC20 function `

Feb '25

Core Contracts

Core Contracts

0.00 usdc • 2 total findings • CodeHawks • aye__aye

#394

medium

Treasury Contract Deposit Function Can Be Frontrun To Deny Protocol Operations

low

Incorrect Initialization of minBoost in BaseGauge Constructor Breaks Core Contract Functionality