https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/d08a6076-9794-423e-b18e-a4d8c0af3e37.jpg

zhuying

Security Researcher

have fun

Contact Me

High

2

Total

Medium

8

Total

$4.07K

Total Earnings

#851 All Time

13x

Payouts

bronze

1x

3rd Places

regular

5x

Top 10

regular

8x

Top 25

All

Sherlock

Code4rena

Cantina

CodeHawks

Feb '25

Usual Labs

Usual Labs

238.32 USDC • Sherlock • zhuying

#24

Core Contracts

Core Contracts

0.00 usdc • 1 total finding • CodeHawks • zhuying

#397

low

Incorrect Initialization of minBoost in BaseGauge Constructor Breaks Core Contract Functionality

Jan '25

Ignite

Ignite

15.29 usdc • CodeHawks • zhuying

#21

Dec '24

Alchemix Transmuter

Alchemix Transmuter

11.67 op • 2 total findings • CodeHawks • zhuying

#26

medium

not adding `claimable` balance to the total assets in `_harvestAndReport` can cause losses.

low

Old router retains token allowance after update

Chainlink Payment Abstraction

Chainlink Payment Abstraction

1,987.07 USDC • Code4rena • zhuying

bronze

Jul '24

Biconomy: Nexus

Biconomy: Nexus

416.11 USDC • 3 total findings • CodeHawks • zhuying

#7

medium

Anyone can call the fallbackFunction because of missing authorization control

medium

Protocol not fully compliant with `EIP-7579`

low

`Nexus.validateUserOp()` violates the EIP-4337 specification

May '24

Beanstalk: The Finale

Beanstalk: The Finale

81.46 USDC • 1 total finding • CodeHawks • zhuying

#34

low

High Risk Denial-of-Service (DoS) Vulnerability in ERC1155 Token Minting Process.

YOLO Games

YOLO Games

198.3 USDC • 1 total finding • Cantina • zhuying

#14

medium

Finding not yet public.

Apr '24

DYAD

DYAD

8.59 USDC • 2 total findings • Code4rena • zhuying

#94

medium

Value of kerosene can be manipulated to force liquidate users

medium

Incorrect deployment / missing contract will break functionality

Beanstalk Part 2

Beanstalk Part 2

748.76 USDC • 1 total finding • CodeHawks • zhuying

#7

medium

```LibWstethEthOracle::getWstethEthPrice``` returns wrong ```wstETH/ETH``` price in some conditions impacting system operations

Feb '24

Jala Swap

Jala Swap

363.37 USDC • 1 total finding • Sherlock • zhuying

#5

medium

The functions about ```permit``` won't work and always revert

Jan '24

Telcoin Platform Audit

Telcoin Platform Audit

2.64 USDC • 1 total finding • Sherlock • zhuying

#9

high

[M-01] The burn function will break the claim function

Oct '23

NextGen

NextGen

0 USDC • 1 total finding • Code4rena • zhuying

#115

high

Attacker can drain all ETH from AuctionDemo when block.timestamp == auctionEndTime