https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/0bb69ba9-fcf2-406e-9683-713be8f765eb.jpg

slylandro

Security Researcher

independent security and formal methods researcher

Contact Me

High

8

Total

Medium

7

Total

$12.45K

Total Earnings

#513 All Time

11x

Payouts

gold

2x

1st Places

regular

3x

Top 10

regular

5x

Top 25

All

Sherlock

Code4rena

Feb '25

Blend V2 Audit + Certora Formal Verification

Blend V2 Audit + Certora Formal Verification

76.71 USDC • 1 total finding • Code4rena • slylandro_star

#27

medium

Potentially sensitive disclosure - 5

Apr '24

Renzo

Renzo

18.2 USDC • 1 total finding • Code4rena • CodeWasp

#41

medium

Pending withdrawals prevent safe removal of collateral assets

DYAD

DYAD

4.1 USDC • 2 total findings • Code4rena • CodeWasp

#106

high

Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine

high

Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply

Panoptic

Panoptic

32.96 USDC • Code4rena • CodeWasp

#18

Mar '24

Mento

Mento

3,571.42 USDC • 1 total finding • Sherlock • slylandro

gold

medium

A staker withdraws funds during a migration and keeps their voting power and rewards while having nothing at stake

PoolTogether

PoolTogether

577.45 USDC • 1 total finding • Code4rena • CodeWasp

#10

medium

Funds locked due to missing transfer check

Feb '24

UniStaker Infrastructure

UniStaker Infrastructure

7,783.56 USDC • Code4rena • CodeWasp

gold
Althea Liquid Infrastructure

Althea Liquid Infrastructure

7.18 USDC • 1 total finding • Code4rena • CodeWasp

#34

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

AI Arena

AI Arena

242.1 USDC • 5 total findings • Code4rena • CodeWasp

#23

high

Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

NFTs can be transferred even if StakeAtRisk remains, so the user's win cannot be recorded on the chain due to underflow, and can recover past losses that can't be recovered(steal protocol's token)

medium

Burner role can not be revoked

Jan '24

Decent

Decent

0.12 USDC • 1 total finding • Code4rena • slylandro_star

#55

high

Anyone can update the address of the Router in the DcntEth contract to any address they would like to set.

Curves

Curves

140.78 USDC • 2 total findings • Code4rena • slylandro_star

#33

high

Whitelised accounts can be forcefully DoSed from buying curveTokens during the presale

medium

Selling will be bricked if all other tokens are withdrawn to ERC20 token