https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/dd2081f4-31b7-48ef-9303-68fcb5b3899a.jpg

theweb3mechanic

Security Researcher

Contact Me

High

12

Total

Medium

19

Total

$21.70K

Total Earnings

#360 All Time

18x

Payouts

silver

1x

2nd Places

regular

5x

Top 10

regular

8x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Jun '25

Panoptic

Panoptic

118.95 USDC • Code4rena • TheWeb3Mechanic

#7

DODO Cross-Chain DEX

DODO Cross-Chain DEX

0.26 USDC • 1 total finding • Sherlock • theweb3mechanic

#72

medium

transfer method prevents the use of USDT token on GatewaySend contract

May '25

LEND

LEND

72.80 USDC • 6 total findings • Sherlock • theweb3mechanic

#33

high

An attacker can use cross chain borrowing to drain another chain

high

Cross chain borrow functionality negelects remote chain debts

high

`_handleValidBorrowRequest` does not scale the previous borrow amount using the current index

medium

Borrow function misapplies single market borrow factor to multi market borrowed value

medium

Baddebts will continue to accrue for some underwater positions

medium

USDT tokens will be permanently stuck and unredeemable

aera-v3

aera-v3

2,948.69 USDC • 1 total finding • Cantina • TheWeb3Mechanic

silver

medium

Finding not yet public.

Extrafi XLend

Extrafi XLend

2,881.35 OP • Sherlock • theweb3mechanic

#5

Findings not publicly available for private contests.

jigsaw-contracts

jigsaw-contracts

67.91 USDC • 1 total finding • Cantina • TheWeb3Mechanic

#56

high

Finding not yet public.

Apr '25

ZKP2P V2

ZKP2P V2

307.71 OP • Sherlock • theweb3mechanic

#7

Findings not publicly available for private contests.

Feb '25

Usual Labs

Usual Labs

97.01 USDC • Sherlock • theweb3mechanic

#31

velvet-v4

velvet-v4

1,003.83 USDC • 2 total findings • Cantina • TheWeb3Mechanic

#13

medium

Finding not yet public.

medium

Finding not yet public.

Jan '25

dahlia-protocol

dahlia-protocol

4,442.93 USDC • 3 total findings • Cantina • Bug-Finders

#5

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

infrared-contracts

infrared-contracts

634.72 USDC • 1 total finding • Cantina • TheWeb3Mechanic

#40

medium

Finding not yet public.

Dec '24

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

68.43 OP • 10 total findings • Sherlock • theweb3mechanic

#29

high

An attacker can redeem all the usdt tokens available in the protocol for a small amount of usda

high

A malicious user can reuse a previously signed `excessProfitCumulativeValue` to steal profit.

high

`Abond_Token.sol::transferfrom` does not correctly update state

high

Logic flaw in `BorrowLib.sol::getOptionFeesTOPay` allows users to bypass the `renewOption` deadline

high

An Attacker can update `downsideProtected`

high

A malicious borrower can make their position immune to `Liquidationtype1`

medium

Profit/Loss will be wrongly updated between concecutive deposits

medium

An attacker can disrupt multisgn quorum on setter functions.

medium

`Ethvolatility` is never verified and can be abused by users

medium

Excess native token sent in `borrowing.sol::renewOptions` is not refunded and can be stolen by other users

Nov '24

Concrete

Concrete

9.86 USDC • Code4rena • TheWeb3Mechanic

#93

hyperlend

hyperlend

293.12 USDC • 1 total finding • Cantina • TheWeb3Mechanic

#14

high

Finding not yet public.

Debita Finance V3

Debita Finance V3

36.56 USDC • 1 total finding • Sherlock • theweb3mechanic

#39

medium

An attacker can delete all lending order leading to a permanent loss of funds and other adverse effects

Oct '24

Era

Era

8,622.34 USDC • CodeHawks • Centaur

#12

Aug '24

ZeroLend One

ZeroLend One

24.22 USDC • 2 total findings • Sherlock • theweb3mechanic

#42

medium

Asset reallocation failure due to incorrect handling of zero allocation

medium

Incorrect stale time check resulting in periods of inactivity

Sentiment V2

Sentiment V2

70.70 USDC • 2 total findings • Sherlock • theweb3mechanic

#37

medium

Ineffective implementation of the pause mechanism in the Superpool

medium

Delisted assets still stands as a collateral