https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/43678336-7c61-4365-9438-50bc80d84070.jpg

werulez99

Security Researcher

Contact Me

High

4

Total

Medium

15

Total

$17.73K

Total Earnings

#545 All Time

11x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

6x

Top 10

All

Sherlock

Code4rena

Cantina

Jan '26

Flying Tulip

Flying Tulip

4,309.47 USDC • Sherlock • Valves

#4

Dec '25

Panoptic: Next Core

Panoptic: Next Core

9,260.89 USDC • Code4rena • Valves

gold
Monolith Stablecoin Factory

Monolith Stablecoin Factory

1,691.10 USDC • 2 total findings • Sherlock • Valves

bronze

high

Borrower can extract unbacked Coin at the expense of the protocol

medium

A single borrower being written off will create unbacked stablecoins for all users

Nov '25

stNXM by EaseDeFi

stNXM by EaseDeFi

4.51 USDC • 4 total findings • Sherlock • werulez99

#36

medium

Duplicate tranche tracking enables share-price inflation and owner withdrawal abuse.

medium

Missing tranche update in extendDeposit causes underpriced shares.

medium

Uniswap V3 liquidity operations lack slippage protection

medium

Oracle APY sanity check weakens over time and stops protecting against price manipulation

Oct '25

Avon-Contracts

Avon-Contracts

524.22 USDC • 5 total findings • Cantina • Valves

#6

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Sep '25

Summer.fi - governance v2

Summer.fi - governance v2

76.81 USDC • 2 total findings • Sherlock • werulez99

#6

medium

Removing a reward token doesn’t reset state and later re-adding lets late stakers steal historical rewards

medium

Malicious callers can throttle USDC/USDT/WBTC rewards by spamming getRewardFor.

Jul '25

GTE Spot CLOB and Router

GTE Spot CLOB and Router

17.52 USDC • 1 total finding • Code4rena • Merulez99

#20

medium

Removing only the tail order from a limit does not reduce tree size, allowing order book to grow indefinitely

Mar '25

Nudge.xyz

Nudge.xyz

610.41 USDC • 1 total finding • Code4rena • HaidutiSec

#6

medium

Anyone can DOS handleReallocation over and over

Feb '25

defi-app-contracts

defi-app-contracts

228.43 USDC • 2 total findings • Cantina • merulz99

#17

high

Finding not yet public.

medium

Finding not yet public.

Jan '25

Plaza Finance

Plaza Finance

1,004.24 USDC • 1 total finding • Sherlock • werulez99

#13

high

#Collateral level Inflation vulnerability

Feb '24

AI Arena

AI Arena

2.06 USDC • 1 total finding • Code4rena • Merulez99

#157

high

Malicious user can stake an amount which causes zero curStakeAtRisk on a loss but equal rewardPoints to a fair user on a win