https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/4cdeb137-ac95-4008-a728-0d8df5c0cd17.jpg

tobi0x18

Web3 Security Researcher

Sherlock Lead Judge

High

8

Total

Medium

11

Total

$8.85K

Total Earnings

#644 All Time

13x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

9x

Top 10

All

Sherlock

Code4rena

Aug '25

USG - Tangent

USG - Tangent

1,760.86 USDC • 8 total findings • Sherlock • tobi0x18

silver

high

Attackers can steal funds by using the `migrateFrom` and `migrateTo` functions

high

The price of PT is not equal to underlying price after expiry

medium

Tokens that don't return a bool in the `transfer` function can't work with ZappingProxy

medium

ZappingProxy can't receive ETH

medium

Oracle for Pendle PT incorrectly assumes the decimal of rate as 18

medium

All market operation assumes the price of USG as 1 USD

medium

The `sUSDe.withdraw` function always reverts

medium

There is no slippage in the liquidation

May '25

Native Smart Contract V2

Native Smart Contract V2

485.20 USDC • Sherlock • tobi0x18

#17

Findings not publicly available for private contests.

LayerEdge - Staking

LayerEdge - Staking

7.19 USDC • 1 total finding • Sherlock • tobi0x18

#7

medium

Users may unexpectedly incur financial losses due to high gas fees

Apr '25

ZKP2P V2

ZKP2P V2

2,170.80 OP • Sherlock • tobi0x18

#4

Findings not publicly available for private contests.

Feb '25

Usual Labs

Usual Labs

1,843.27 USDC • Sherlock • tobi0x18

#10

Rova

Rova

0.04 USDC • 1 total finding • Sherlock • tobi0x18

bronze

medium

The `updateParticipation` function can be DoSed due to incorrect check

Dec '24

Oku's New Order Types Contract Contest

Oku's New Order Types Contract Contest

24.97 OP • 3 total findings • Sherlock • tobi0x18

#25

high

Vulnerability in handling orders in the same block

high

No resetting the allowance of the token to 0 in the `execute` functions

high

Discrepancy in the `createOrder()` function of the `Bracket` and the `StopLimit` contract

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

1,011.36 USDC • 3 total findings • Sherlock • tobi0x18

#7

high

Malicious attackers can steal funds by buying and selling votes in one transaction from the reputation market

high

Fee Mismanagement in the `ReputationMarket.buyVotes` Function

medium

Incorrect fees calculation in the `EthosVouch.applyFees` function causes the voucher's loss of funds

Nouns DAO - Auction Streams

Nouns DAO - Auction Streams

417.06 USDC • Sherlock • tobi0x18

#14

Telcoin Update #2

Telcoin Update #2

292.86 USDC • Sherlock • tobi0x18

#7

Oct '24

predict.fun lending market

predict.fun lending market

337.23 USDC • 1 total finding • Sherlock • tobi0x18

#6

medium

An incorrect fee calculation may result in the application of two different fee rates

Sep '24

Saffron Lido Vaults

Saffron Lido Vaults

284.56 USDC • 1 total finding • Sherlock • tobi0x18

bronze

medium

An incorrect income distribution will lead to fund losses during slashing

Jun '24

Vultisig

Vultisig

214.3 USDC • 1 total finding • Code4rena • tobi0x18

#17

high

Most users won't be able to claim their share of Uniswap fees