https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/84eb203c-0ffc-40b8-a79c-dad366ad7e0c.jpg

sparrow

Security Researcher

Protect Your Web3 Protocol With Our Expert Security Solutions

Contact Me

High

2

Total

Medium

13

Total

$11.03K

Total Earnings

#548 All Time

24x

Payouts

silver

1x

2nd Places

regular

8x

Top 10

regular

17x

Top 25

All

Code4rena

May '25

Audit 507

Audit 507

54 USDC • Code4rena • Sparrow

#26

Mar '25

StarkWare Perps

StarkWare Perps

315.79 USDC • Code4rena • Sparrow

#20

Feb '25

Blend V2 Audit + Certora Formal Verification

Blend V2 Audit + Certora Formal Verification

4,178.13 USDC • 1 total finding • Code4rena • Sparrow

#8

medium

Edge case breaks APR cap calculation and leads to excessive fee extraction from the pool

THORWallet

THORWallet

165.79 USDC • Code4rena • Sparrow

#4

Virtuals Protocol

Virtuals Protocol

947.37 USDC • Code4rena • Sparrow

#8

Initia Cosmos

Initia Cosmos

663.16 USDC • Code4rena • Sparrow

#7

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • Sparrow

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

IQ AI

IQ AI

3.58 USDC • 1 total finding • Code4rena • Sparrow

#16

medium

Ineffective proposal threshold validation allows setting arbitrary high values

Pump Science

Pump Science

221.05 USDC • Code4rena • Sparrow

#7

Dec '24

Flex Perpetuals

Flex Perpetuals

862.48 USDC • 1 total finding • Code4rena • Sparrow

silver

medium

Missing slippage protection in `AerodromeDexter.sol` `swapExactTokensForTokens()`

Nov '24

MANTRA DEX

MANTRA DEX

12.22 USDC • 1 total finding • Code4rena • Sparrow

#22

medium

`withdraw_liquidity` lacks slippage protection

Concrete

Concrete

635.79 USDC • Code4rena • Sparrow

#25

Chainlink

Chainlink

1,473.68 USDC • Code4rena • Sparrow

#5

Oct '24

Kleidi

Kleidi

0 USDC • Code4rena • Sparrow

#12

Aug '24

Chakra

Chakra

0.02 USDT • 1 total finding • Code4rena • Sparrow

#67

high

SettlementSignatureVerifier is missing check for duplicate validator signatures

Superposition

Superposition

1.26 USDC • 1 total finding • Code4rena • Sparrow

#32

medium

_onTransferReceived() does not work as intended

Phi

Phi

21.42 USDC • 1 total finding • Code4rena • Sparrow

#38

high

Signature replay in `createArt` allows to impersonate artist and steal royalties

Axelar Network

Axelar Network

947.37 USDC • Code4rena • Sparrow

#5

Jul '24

LoopFi

LoopFi

220.95 USDC • 2 total findings • Code4rena • Sparrow

#33

medium

`PendleLPOracle::_fetchAndValidate` uses Chainlink's deprecated `answeredInRound`

medium

`SwapAction.sol#balancerSwap` does not support native ETH as input token.

Optimism Superchain

Optimism Superchain

0 OP • Code4rena • Sparrow

#14

May '24

Olas

Olas

232.44 USDC • 1 total finding • Code4rena • Sparrow

#12

medium

Incorrect Handling of Last Nominee Removal in `removeNominee` Function

Predy

Predy

55.39 USDC • 3 total findings • Code4rena • Sparrow

#24

medium

incorrect price for negative ticks due to lack of rounding down

medium

Liquidity manipulation is possible when trading

medium

Chainlink's `latestRoundData` might return stale or incorrect results

Apr '24

Renzo

Renzo

0 USDC • Code4rena • Sparrow

#58

NOYA

NOYA

19.18 USDC + NOYA stars • 1 total finding • Code4rena • Sparrow

#82

medium

Chainlink connector doesn’t check for the Min / Max prices returned