https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

songyuqi

Security Researcher

Contact Me

High

2

Total

Medium

2

Total

$1.68K

Total Earnings

#2440 All Time

5x

Payouts

regular

1x

Top 10

regular

2x

Top 25

regular

2x

Top 50

All

Sherlock

Dec '25

Monolith Stablecoin Factory

Monolith Stablecoin Factory

1,654.62 USDC • 1 total finding • Sherlock • songyuqi

#6

high

There is a severe arithmetic vulnerability in the handling of 'Free Debt Shares' and the 'Epoch/Rebase' mechanism. This leads to an integer overflow, resulting in a Denial of Service (DoS) attack that renders the contract permanently paralyzed.

Oct '25

Index Fun Order Book

Index Fun Order Book

2.16 USDC • 1 total finding • Sherlock • songyuqi

#14

high

it uses the buyer’s information (buyOrder.user) to fetch the fee rate, but the fee is actually deducted from the seller’s receivable.

Saffron Fixed Income Vaults

Saffron Fixed Income Vaults

2.80 USDC • Sherlock • songyuqi

#74

Sep '25

Super DCA Liquidity Network

Super DCA Liquidity Network

0.02 OP • 1 total finding • Sherlock • songyuqi

#51

medium

the rewards for the entire period between deployment and the first stake are incorrectly allocated to the first staker.

Ammplify

Ammplify

23.18 USDC • 1 total finding • Sherlock • songyuqi

#67

medium

Condition Too Strict When Removing Liquidity in the adjustMaker function.