https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/fbf5ef3d-5f87-4c34-b3f2-8388f6794f33.jpg

vangrim

Security Researcher

Web3 Security Researcher 🕵🏻 | Red Team @QuillAudits 🟥 | Dreamer at @matos_DAO 🌠 | ETHDenver and ETHGlobal finalist 🏆 | Ex-Privacy Lawyer 🧑‍⚖️

Contact Me

High

4

Total

Medium

12

Total

$550.00

Total Earnings

#1619 All Time

12x

Payouts

bronze

1x

3rd Places

regular

1x

Top 10

regular

4x

Top 25

All

Sherlock

Code4rena

Nov '25

stNXM by EaseDeFi

stNXM by EaseDeFi

0.01 USDC • 1 total finding • Sherlock • vangrim

#52

high

Attacker will steal funds from depositors by manipulating share price via Uniswap V3 spot price

Inverse Finance - Junior Tranche

Inverse Finance - Junior Tranche

12.54 USDC • 1 total finding • Sherlock • vangrim

bronze

medium

ERC-4626 violation: jDOLA vault's maxDeposit() and maxMint() return infinite capacity when MAX_SHARES limit exists, causing user reverts on deposits

Sep '25

Dango DEX

Dango DEX

10.58 USDC • 1 total finding • Sherlock • vangrim

#21

medium

Attacker will brick XYK pair and lock initial LP funds via a one-sided first deposit

Jul '25

Malda

Malda

248.12 USDC • 3 total findings • Sherlock • vangrim

#25

medium

EverclearBridge will fail all cross-chain transfers due to missing token transfer

medium

Rebalancer will permanently block rebalances for a route due to stale window size check

medium

Users will receive fewer mTokens than expected during migration due to incorrect slippage calculation with wrong token decimals

Notional Exponent

Notional Exponent

134.23 USDC • 1 total finding • Sherlock • vangrim

#34

medium

Protocol will brick or lose funds on non-mainnet deployments

Apr '25

Burve

Burve

9.46 USDC • 1 total finding • Sherlock • vangrim

#29

high

User can withdraw tokens without paying the intended tax due to an uninitialised variable in `removeValueSingle`’s fee calculation

Kinetiq

Kinetiq

21.68 USDC • 2 total findings • Code4rena • vangrim

#30

high

Users Who Queue Withdrawal Before A Slashing Event Disadvantage Users Who Queue After And Eventually Leads To Loss Of Funds For Them

medium

Incorrect Balance Check in Validator Redelegation Process May Block Legitimate Rebalancing Operations

Jan '25

Next Generation

Next Generation

3.55 USDC • 1 total finding • Code4rena • vangrim

#15

medium

Lack of deadline check in forwarded request

Nov '23

Canto Application Specific Dollars and Bonding Curves for 1155s

Canto Application Specific Dollars and Bonding Curves for 1155s

1.37 USDC • 1 total finding • Code4rena • vangrim

#31

medium

No slippage protection for Market functions

Oct '23

NextGen

NextGen

0 USDC • 1 total finding • Code4rena • vangrim

#115

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime

Sep '23

Allo V2

Allo V2

62.52 USDC • 2 total findings • Sherlock • vangrim

#47

medium

[MEDIUM]Allo#_fundPool

medium

[MEDIUM] QVBaseStrategy.sol

Aug '23

Dopex

Dopex

46.25 USDC • 1 total finding • Code4rena • vangrim

#94

medium

A malicious early depositor can manipulate the `LP-Token` price per share to take an unfair share of future user deposits