https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/dd2081f4-31b7-48ef-9303-68fcb5b3899a.jpg

theweb3mechanic

Security Researcher

Contact Me

High

8

Total

Medium

12

Total

$14.60K

Total Earnings

#426 All Time

10x

Payouts

regular

2x

Top 10

regular

4x

Top 25

regular

10x

Top 50

All

Sherlock

Cantina

CodeHawks

Apr '25

ZKP2P V2

ZKP2P V2

307.71 OP • Sherlock • theweb3mechanic

#7

Findings not publicly available for private contests.

Feb '25

Usual Labs

Usual Labs

97.01 USDC • Sherlock • theweb3mechanic

#31

Jan '25

dahlia-protocol

dahlia-protocol

4,442.93 USDC • 3 total findings • Cantina • Bug-Finders

#5

high

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

infrared-contracts

infrared-contracts

634.72 USDC • 1 total finding • Cantina • TheWeb3Mechanic

#40

medium

Finding not yet public.

Dec '24

Autonomint Colored Dollar V1

Autonomint Colored Dollar V1

68.43 OP • 10 total findings • Sherlock • theweb3mechanic

#29

high

An attacker can redeem all the usdt tokens available in the protocol for a small amount of usda

high

A malicious user can reuse a previously signed `excessProfitCumulativeValue` to steal profit.

high

`Abond_Token.sol::transferfrom` does not correctly update state

high

Logic flaw in `BorrowLib.sol::getOptionFeesTOPay` allows users to bypass the `renewOption` deadline

high

An Attacker can update `downsideProtected`

high

A malicious borrower can make their position immune to `Liquidationtype1`

medium

Profit/Loss will be wrongly updated between concecutive deposits

medium

An attacker can disrupt multisgn quorum on setter functions.

medium

`Ethvolatility` is never verified and can be abused by users

medium

Excess native token sent in `borrowing.sol::renewOptions` is not refunded and can be stolen by other users

Nov '24

hyperlend

hyperlend

293.12 USDC • 1 total finding • Cantina • TheWeb3Mechanic

#14

high

Finding not yet public.

Debita Finance V3

Debita Finance V3

36.56 USDC • 1 total finding • Sherlock • theweb3mechanic

#39

medium

An attacker can delete all lending order leading to a permanent loss of funds and other adverse effects

Oct '24

Era

Era

8,622.34 USDC • CodeHawks • Centaur

#12

Aug '24

ZeroLend One

ZeroLend One

24.22 USDC • 2 total findings • Sherlock • theweb3mechanic

#42

medium

Asset reallocation failure due to incorrect handling of zero allocation

medium

Incorrect stale time check resulting in periods of inactivity

Sentiment V2

Sentiment V2

70.70 USDC • 2 total findings • Sherlock • theweb3mechanic

#37

medium

Ineffective implementation of the pause mechanism in the Superpool

medium

Delisted assets still stands as a collateral