https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/fc8e52f7-f9d1-4ffa-aca4-27da6bf1a3e3.jpg

zanderbyte

Security Researcher

Smart Contract Security Researcher

Contact Me

High

8

Total

Medium

15

Total

$11.83K

Total Earnings

#494 All Time

14x

Payouts

gold

1x

1st Places

bronze

1x

3rd Places

regular

8x

Top 10

All

Sherlock

Code4rena

Cantina

Apr '25

BitVault

BitVault

845.69 USDC • 1 total finding • Code4rena • zanderbyte

#4

medium

The current implementation is incompatible with `WBTC` as collateral token

Jan '25

Liquid Ron

Liquid Ron

0 USDC • 1 total finding • Code4rena • zanderbyte

#12

medium

Incorrect Logic in onlyOperator Modifier Leading to Denial-of-Service for Authorized Operators Across Critical Functions

doppler-contracts

doppler-contracts

3,153.73 USDC • 2 total findings • Cantina • zanderbyte

#7

high

Finding not yet public.

medium

Finding not yet public.

Dec '24

Mach Finance

Mach Finance

615.38 USDC • 1 total finding • Sherlock • zanderbyte

gold

medium

`PythOracle` does not validate price freshness, leading to potential stale prices

Flex Perpetuals

Flex Perpetuals

62.48 USDC • 1 total finding • Code4rena • zanderbyte

#4

medium

Missing slippage protection in `AerodromeDexter.sol` `swapExactTokensForTokens()`

SecondSwap

SecondSwap

80.31 USDC • 4 total findings • Code4rena • zanderbyte

#32

medium

Incorrect referral fee calculations

medium

Missing option to remove tokens from the `isTokenSupport` mapping can result in huge financial loss for users and the protocol

medium

Creator of one vesting plan can affect vesting plans created by other users.

medium

Listing potential can not be purchased with discounted price

bima-money

bima-money

1,642.29 USDC • 1 total finding • Cantina • zanderbyte

#16

high

Finding not yet public.

Nov '24

hyperlend

hyperlend

43.12 USDC • 1 total finding • Cantina • zanderbyte

#16

high

Finding not yet public.

Aug '24

zetachain-protocol

zetachain-protocol

3,481.36 USDC • 4 total findings • Cantina • zanderbyte

#9

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

medium

Finding not yet public.

Jul '24

Basin

Basin

772.57 USDC • 2 total findings • Code4rena • zanderbyte

bronze

high

Incorrectly assigned `decimal1` parameter upon decoding

high

`WellUpgradeable` can be upgraded by anyone

Karak Restaking

Karak Restaking

924.5 USDC • 1 total finding • Code4rena • zanderbyte

#8

high

Slashing NativeVault will lead to locked ETH for the users

Jun '24

Size

Size

6.22 USDC • 2 total findings • Code4rena • zanderbyte

#57

high

Users won't liquidate positions because the logic used to calculate the liquidator's profit is incorrect

medium

Fragmentation fee is not taken if user compensates with newly created position

May '24

Arbitrum BoLD

Arbitrum BoLD

0 USDC • Code4rena • zanderbyte

#10

Feb '24

opal-contracts

opal-contracts

199.82 USDC • 2 total findings • Cantina • zanderbyte

#29

high

Finding not yet public.

medium

Finding not yet public.