https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

windhustler

Security Researcher

Contact Me

High

10

Total

Medium

7

Total

$19.54K

Total Earnings

#400 All Time

7x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

3x

Top 10

All

Sherlock

Code4rena

Nov '24

IVX

IVX

Collaborative Audit • Sherlock • windhustler

Apr '24

DYAD

DYAD

8.69 USDC • 2 total findings • Code4rena • windhustler

#93

high

Users can get their Kerosene stuck until TVL becomes greater than Dyad's supply

medium

Value of kerosene can be manipulated to force liquidate users

Jan '24

Decent

Decent

3,078.89 USDC • 3 total findings • Code4rena • windhustler

gold

high

Due to missing checks on minimum gas passed through LayerZero, executions can fail on the destination chain

medium

Potential loss of capital due to fixed fee calculations

medium

Permanent loss of tokens if swap data gets outdated

Nov '23

IVX

IVX

Collaborative Audit • Sherlock • windhustler

Oct '23

ENS

ENS

102.56 USDC • Code4rena • windhustler

#8

Sep '23

Maia DAO - Ulysses

Maia DAO - Ulysses

145.41 USDC • 3 total findings • Code4rena • windhustler

#35

high

All tokens can be stolen from `VirtualAccount` due to missing access modifier

medium

Message channels can be blocked resulting in DoS

medium

If RootBridgeAgent.lzReceiveNonBlocking reverts internally, the native token sent by relayer to RootBridgeAgent is left in RootBridgeAgent

Aug '23

veRWA

veRWA

9.82 USDC • Code4rena • windhustler

#52

Jul '23

Tapioca DAO

Tapioca DAO

16,166.83 USDC • 9 total findings • Code4rena • windhustler

bronze

high

Refund mechanism for failed cross-chain transactions does not work

high

Attacker can block LayerZero channel due to missing check of minimum gas passed

high

Attacker can block LayerZero channel due to variable gas cost of saving payload

high

TOFT `triggerSendFrom` can be used to steal all the balance

high

TOFT `removeCollateral` can be used to steal all the balance

high

TOFT `exerciseOption` can be used to steal all underlying erc20 tokens

high

TOFT leverageDown always fails if TOFT is a wrapper for native tokens

medium

TOFT `exerciseOption` fails due to not passing `msg.value` properly

medium

Airdropped tokens can be stolen by a bot

Apr '22

Phuture Finance contest

Phuture Finance contest

29.76 USDC • Code4rena • windhustler

#32