https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

smbv-1923

Security Researcher

Contact Me

High

20

Total

Medium

28

Total

$9.73K

Total Earnings

#592 All Time

30x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

12x

Top 10

All

Sherlock

Code4rena

Cantina

CodeHawks

May '25

LEND

LEND

1.62 USDC • 1 total finding • Sherlock • smbv-1923

#108

high

Inaccurate Exchange Rate Calculation Can Undercredit Users During Redemption

Apr '25

mighty-contracts

mighty-contracts

821.96 USDC • 6 total findings • Cantina • smbv19192323

#7

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

liquidity-book-vaults

liquidity-book-vaults

478.45 USDC • 3 total findings • Cantina • smbv19192323

#13

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Feb '25

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • smbv-1923

bronze

medium

updateParticipation() flaw enables attacker to claim more refund currency tokens than intended.

Jan '25

infrared-contracts

infrared-contracts

1,023.59 USDC • 1 total finding • Cantina • smbv19192323

#31

high

Finding not yet public.

Dec '24

Tally ARB Staker

Tally ARB Staker

1,047.89 USDC • Sherlock • smbv-1923

#4

Flex Perpetuals

Flex Perpetuals

62.48 USDC • 1 total finding • Code4rena • smbv-1923

#4

medium

Missing slippage protection in `AerodromeDexter.sol` `swapExactTokensForTokens()`

Idle Finance Credit Vaults

Idle Finance Credit Vaults

600.44 USDC • Sherlock • smbv-1923

#7

Findings not publicly available for private contests.

SecondSwap

SecondSwap

0.03 USDC • 2 total findings • Code4rena • smbv-1923

#66

high

Users can claim more that their actual allotment

medium

Incorrect referral fee calculations

Numa

Numa

579.94 USDC • 1 total finding • Sherlock • smbv-1923

#10

high

Vault inflation causing victims to lose their full deposit

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

2.51 OP • 3 total findings • Sherlock • smbv-1923

#63

high

`redeemUSDT()` Prone to Exploitation Through Input Price Manipulation

high

Lack of access control in `updateDownsideProtected()` would lead to DOS.

medium

`lastEventTime` gets updated wrongly during withdraw of collateral

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

74.96 USDC • 3 total findings • Sherlock • smbv-1923

#23

high

Double Accounting of fees in `buyVotes()`

high

Fee taken on unused amount is not returned during `_calculateBuy()`

medium

No slippage protection in sellVotes()

Extra Finance

Extra Finance

1,665.90 OP • Sherlock • smbv-1923

bronze

Findings not publicly available for private contests.

Chiliz Chain System Contracts

Chiliz Chain System Contracts

227.64 USDC • Sherlock • smbv-1923

#12

Findings not publicly available for private contests.

Telcoin Update #2

Telcoin Update #2

257.15 USDC • Sherlock • smbv-1923

#9

Sep '24

Royco Protocol

Royco Protocol

217.39 USDC • 6 total findings • Cantina • smbv19192323

#29

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Aug '24

Sentiment V2

Sentiment V2

1,542.85 USDC • 1 total finding • Sherlock • smbv-1923

#5

high

Loss of users fund through share inflation attack in `Pool.sol`

Jul '24

TraitForge

TraitForge

187.21 USDC • 3 total findings • Code4rena • smbv-1923

#28

high

Number of entities in generation can surpass the 10k number

high

Wrong minting logic based on total token count across generations

medium

Users' ability to nuke will be DoSed for three days after putting NFTs up for sale and cancelling the sale

Union Finance Update #2

Union Finance Update #2

93.79 USDC • 1 total finding • Sherlock • smbv-1923

#10

medium

Use a safe transfer helper library for ERC20 transfers

May '24

YOLO Games

YOLO Games

556.67 USDC • 2 total findings • Cantina • smbv19192323

#10

medium

Finding not yet public.

medium

Finding not yet public.

Apr '24

Teller Finance

Teller Finance

17.69 USDC • 1 total finding • Sherlock • smbv-1923

#32

medium

Share Inflation Attack via Internal Accounting

TITLES Publishing Protocol

TITLES Publishing Protocol

1.75 USDC • 2 total findings • Sherlock • smbv-1923

#54

medium

For Loop would create issue while calling `mintBatch()`

medium

Excessive ETH passed during mint() would not be refunded

Mar '24

Smart-contracts

Smart-contracts

1.7 USDC • 1 total finding • Cantina • smbv19192323

#42

medium

Finding not yet public.

PoolTogether

PoolTogether

1.47 USDC • 1 total finding • Code4rena • smbv-1923

#29

high

Any fee claim lesser than the total `yieldFeeBalance` as unit of shares is lost and locked in the `PrizeVault` contract

Telcoin Platform Audit Update

Telcoin Platform Audit Update

228.70 USDC • 1 total finding • Sherlock • smbv-1923

silver

medium

No checks to prevent Blacklisted user from using protocol's function

Jan '24

MorpheusAI

MorpheusAI

24.17 USDC • 2 total findings • CodeHawks • smbv1923

#19

low

Any User can mint any amount of WStETH in the WStETHMock.sol and StETHMock.sol

low

Create Pool in Mock Distribution is missing validations; allowing duplicates, wrong decreaseInterval value and payoutStart value

Dec '23

The Standard

The Standard

1.43 USDC • 2 total findings • CodeHawks • smbv1923

#86

medium

Missing deadline check allow pending transactions to be maliciously executed

medium

Fees are hardcoded to 3000 in ExactInputSingleParams

Aug '23

Sparkn

Sparkn

7.55 USDC • 2 total findings • CodeHawks • smbv1923

#59

low

If a winner is blacklisted on any of the tokens they can't receive their funds

low

Precision loss/Rounding to Zero in `_distribute()`

Jul '23

Beedle - Oracle free perpetual lending

Beedle - Oracle free perpetual lending

6.68 USDC • 4 total findings • CodeHawks • smbv1923

#164

high

Sandwich attack to steal all ERC-20 tokens in the Fees contract

high

Token spending by Uniswap router doesn't get approved

medium

The `borrow` and `refinance` functions can be front-run by the pool lender to set high interest rates

medium

No expiration deadline leads to losing a lot of funds

Foundry DeFi Stablecoin CodeHawks Audit Contest

Foundry DeFi Stablecoin CodeHawks Audit Contest

0.00 USDC • 1 total finding • CodeHawks • smbv1923

#163

medium

Chainlink oracle will return the wrong price if the aggregator hits `minAnswer`