https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

ydlee

Security Researcher

Contact Me

High

11

Total

Medium

18

Total

$4.64K

Total Earnings

#765 All Time

21x

Payouts

bronze

1x

3rd Places

regular

4x

Top 10

regular

13x

Top 25

All

Sherlock

Mar '25

PinLink: RWA-Tokenized DePIN Marketplace

PinLink: RWA-Tokenized DePIN Marketplace

50.26 USDC • Sherlock • ydlee

#26

Symmio, Staking and Vesting

Symmio, Staking and Vesting

0.00 USDC • 1 total finding • Sherlock • ydlee

#18

medium

Users can invoke `notifyRewardAmount()` with a dust reward amount to reduce the reward rate.

Jan '25

Plaza Finance

Plaza Finance

1.98 USDC • 1 total finding • Sherlock • ydlee

#92

high

The calculation of fees in `Pool.sol` is incorrect.

Aave v3.3

Aave v3.3

471.89 USDC • Sherlock • ydlee

#49

Dec '24

Tally ARB Staker

Tally ARB Staker

311.60 USDC • Sherlock • ydlee

#11

Nov '24

Ethos Network Financial Contracts

Ethos Network Financial Contracts

72.48 USDC • 2 total findings • Sherlock • ydlee

#25

high

Users may pay more fees than they should when buying votes.

high

The fees should not be added to the `marketFunds` in the `buyVotes` function.

Debita Finance V3

Debita Finance V3

604.16 USDC • 5 total findings • Sherlock • ydlee

#11

high

The `sellNFT` function transfers the NFT to the `buyOrder.sol` contract instead of the buyer.

medium

A lending offer can be canceled repeatedly.

medium

The precision loss in the fee percentage for connecting offers results in the borrower paying less than the expected fee.

medium

Incorrect minimum fee is used to adjust the loan fee, which may prevent the borrower from extending the loan.

medium

In `extendLoan`, the `maxDeadline` instead of `maxDuration` is used to calculate the fees, which may cause the borrower to pay more fees.

Sep '24

Flayer

Flayer

82.59 USDC • 3 total findings • Sherlock • ydlee

#57

high

Users can obtain about a floor liquidity for any liquid duration without paying any fees.

high

User's collection tokens may be locked in the `CollectionShutdown.sol` contract if the shutdown process is canceled.

medium

Modifying the listing price will result in an overcharge of tax.

Aug '24

Cork Protocol

Cork Protocol

3.41 USDC • 1 total finding • Sherlock • ydlee

#17

medium

Modifier `LVDepositNotPaused` checks the `isWithdrawalPaused` instead of the `isDepositPaused`.

Winnables Raffles

Winnables Raffles

0.76 USDC • 1 total finding • Sherlock • ydlee

#38

medium

Admin cannot deny roles to other users.

Jul '24

MakerDAO Endgame

MakerDAO Endgame

390.51 USDC • Sherlock • ydlee

#76

MagicSea - the native DEX on the IotaEVM

MagicSea - the native DEX on the IotaEVM

231.85 USDC • 2 total findings • Sherlock • ydlee

#14

high

The checking on whether the lock time of the position is sufficient for voting is incorrect

medium

If the approver renews or extends a lock position, the position's current rewards are transferred to the approver instead of the position owner.

May '24

PoolTogether: The Prize Layer for DeFi

PoolTogether: The Prize Layer for DeFi

719.39 USDC • 2 total findings • Sherlock • ydlee

#13

medium

For a new `drawId`, `startDraw` always reverts if the time elapsed for the first `startDraw` exceeds the auction duration.

medium

Prize winners can set claim hooks to revert `claimPrize` from others to save the claim rewards.

Napier Finance - LST/LRT Integrations

Napier Finance - LST/LRT Integrations

118.68 USDC • 1 total finding • Sherlock • ydlee

#14

medium

Incorrect checking in `receiveFlashLoan` can cause `swapETHForYt` to fail unexpectedly.

Apr '24

TITLES Publishing Protocol

TITLES Publishing Protocol

1.75 USDC • 2 total findings • Sherlock • ydlee

#54

medium

Excess mint fees are not returned to the minter as expected.

medium

`mintBatch` always reverts when minting for multiple works, breaking the core contract functionality.

Mar '24

Axis Finance

Axis Finance

43.00 USDC • 1 total finding • Sherlock • ydlee

#27

medium

Pre-funded `FPAM` auctions may lead seller to lose funds.

Zap Protocol

Zap Protocol

857.22 USDC • 3 total findings • Sherlock • ydlee

bronze

high

Users lose some tax refunds when making claims.

medium

`updateUserDeposit` does not support Blast chain's native token.

medium

Users blocked by `blockClaim` can still make claims.

Jan '24

Telcoin Platform Audit

Telcoin Platform Audit

2.64 USDC • 1 total finding • Sherlock • ydlee

#9

high

The last council member cannot claim his allocated TELCOIN after someone's token is burnt.

Truflation

Truflation

90.28 USDC • 1 total finding • Sherlock • ydlee

#9

high

Users can claim more tokens than they staked during cliff period.

Nov '23

Nouns Builder

Nouns Builder

21.94 USDC • 1 total finding • Sherlock • ydlee

#9

high

The first founder lose a portion of his token ownership when `reservedUntilTokenId >= 100`.

Convergence

Convergence

559.66 USDC • 1 total finding • Sherlock • ydlee

#11

medium

A token owner cannot remove one mgCvg delegation when he already delegates to `maxMgDelegatees` addresses.