https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/dfbb1b2c-3f1e-4b80-b32d-f9f8f05724fb.jpg

usmannk

Security Researcher

Immunefi top 10 Especially experienced in go/rust/L1/L2/bridge research.

Contact Me

High

1

Solo

12

Total

Medium

4

Solo

7

Total

$52.28K

Total Earnings

#173 All Time

8x

Payouts

gold

1x

1st Places

silver

1x

2nd Places

regular

4x

Top 10

All

Sherlock

Code4rena

Immunefi

Jul '24

Audit Comp | Shardeum: Core

Audit Comp | Shardeum: Core

18,882 USDC • 2 total findings • Immunefi • usmannk

#7

high

Finding not yet public.

high

Finding not yet public.

Mar '23

Notional Update #2

Notional Update #2

4,285.71 USDC • 2 total findings • Sherlock • usmannk

silver

high

Liquidations are impossible for some Curve pools

medium

Vault cannot be deployed properly for newer Curve pools

Feb '23

Surge

Surge

2,560.87 USDC • 4 total findings • Sherlock • usmannk

gold

high

Pools will be broken if tokens have different decimal amounts

high

Attackers may steal loan tokens from pool depositors

medium

Attackers can force surge to never update the collateralization ratio

medium

Attackers may skip the collateral ratio recovery duration to inflate collateralization ratios and steal funds

OlympusDAO

OlympusDAO

74.58 USDC • 1 total finding • Sherlock • usmannk

#30

high

Attackers may steal reward tokens due to incorrect withdrawal accounting.

OpenQ

OpenQ

168.62 USDC • 3 total findings • Sherlock • usmannk

#27

high

Bounties can be rendered nonfunctional by depositing and refunding an NFT.

high

Claims on Atomic Bounties can be forced to revert by depositing malicious ERC20s.

medium

It is impossible to reduce the quantity of a bounty's payout tiers

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

10.39 USDC • 3 total findings • Code4rena • usmannk

#79

high

Protocol fees can be withdrawn multiple times in `Erc20Quest`

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts

medium

Users may not claim Erc1155 rewards when the Quest has ended

Optimism

Optimism

26,224.92 USDC • 1 total finding • Sherlock • usmannk

#6

medium

Crafted p2p spam can render nodes permanently unable to process L2 blocks

Cooler

Cooler

78.74 USDC • 3 total findings • Sherlock • usmannk

#25

high

Protocol may ignore failed transfers

high

Loans may be rolled over to infinity

medium

`toggleRoll()` may be frontran