Just hit Top 50 in the Notional Exponent contest + secured my first Sherlock payout 🏆💰
The grind finally paying off 🙌
Curious — how long did it take YOU to land your first Sherlock win? 👀
🚨 The Great Lock-In Period starts TODAY 🚨
Whether you’re a 🛡️ web3 security gigachad or just a rookie taking your first swing — now’s the time to lock in and prove your skills. ⚡️
Who’s ready? 👀
Everyone knows ERC4626 and how it works. But not everyone knows all the specs from the EIP.
Here is a bug that comes from not being fully compliant with ERC4626.
Just by researching stuff and diving deep you can find bugs.
github.com/sherlock-audit…
🚨 Calling all aspiring & alpha Web3 security researchers!
If you’re from 🇰🇪 Kenya or 🇹🇿 Tanzania, you can DM me for the Discord invite link or hit up @0xodus
Big things loading… don’t miss out 👀🔥
It's now or never guys. I've decided to challenge myself and I'm glad that @sherlockdefi made this opportunity for me to audit the neutrl protocol codebase.
I humbly accept this challenge @spearbit@mikeleffer 🙏🏿
It's now or never guys. I've decided to challenge myself and I'm glad that @sherlockdefi made this opportunity for me to audit the neutrl protocol codebase.
I humbly accept this challenge @spearbit@mikeleffer 🙏🏿
Hey @spearbit — if I uncover bugs in the Neutrl protocol you audited and finish in the Top 20, will you make me your intern? 🐞🔍 Ready to bring fresh curiosity and energy—let’s raise the bar together!
You can now explore 3,376+ findings from Zokyo’s audits on Solodit.
This is the highest number among all Web3 security firms.
Here’s how to filter and make the most out of it 👇
🧠 Heuristic 101:
dealing with CDP protocol. P2.
- Ensure the liquidate() call uses fresh, accurate exchange-rates—not stale oracle data.
- If a collateral token is blacklisted,inactive,or disabled, only block new activity—not exits,withdrawals, repayments,or liquidations.
✨ Just wrapped up auditing the Malda contest on the @sherlockdefi platform and reported 6 High-severity issues! 🕵️♂️🔍
Grateful for the intense journey and excited about the impact—big thanks to the Sherlock community for the opportunity! 🙏
Wrapped up the Plume Attackathon on @immunefi
Submitted 2 insights 💡 + 1 low 🐜 — now playing the waiting game 🎯
Fingers crossed they get accepted & validated 🤞⚡️
On to the next hunt 🚀
🚨 Just bagged my first-ever finding on the Sherlock platform! 🕵️♂️🔍
After grinding for so long & eating L’s, I’ve finally broken the Sherlock curse 🪄💥
Feels surreal that I shall finally see my name on that leaderboard.
🧠 Heuristic 101:
dealing with CDP protocol. P1.
- Do partial liquidations worsen borrower positions?
- does the isLiquidatable function gives the status of positions accurately?
- does minting of debt(stable Coin) rely on querying oracle price? if so, depegs can happen 🤷♂️
...
🧠 Heuristic 101:
If Function A sets a cooldown and Function B only runs after cooldown expires, assess whether calling A again resets/extending the cooldown. That can block B indefinitely—critical when auditing time‑sensitive liquidations.
🔍 Want a deeper understanding of how liquid staking truly works? Shadow‑audit Mystic Finance’s liquid staking module on @cantinaxyz 🛠️ It’s filled with high‑severity & medium‑severity findings—a golden playground to sharpen your DeFi audit skills.
62 Followers 268 FollowingI spent the last 4 years building software for clients across the globe now I am securing web3 by auditing and researching.
Web3 Security Researcher
263 Followers 2K FollowingOn the path to becoming a cybersecurity expert. Currently building skills in penetration testing and auditing smart contracts.
77K Followers 765 FollowingEnd-to-end Cybersecurity consulting team leading the industry, supporting organizations, and giving back. #Hacktheplanet
Blogs, news, webinars, and tools!
101K Followers 145 FollowingA portable multi-tool device in a toy-like body for pentesters and hardware geeks. Buy worldwide here ➡️ https://t.co/n09EKVnqri
151 Followers 18 FollowingUSC Iovine & Young alum (100% scholarship) • Tech x Design x Biz • On a mission to break into GTM at an AI startup • Sharing what I learn along the way
2K Followers 492 FollowingAcknowledged by Google, Yahoo, U.S. Department of Defense, Tiktok, Logitech, Sony, MTN Group, SEGA and many more.
https://t.co/j7oWJ8FXQ9
20 Followers 88 FollowingI help founders sleep better by securing their contracts — before hackers get to them. Send a DM for a private audit — fast, reliable, secure.🚀
1.2M Followers 2 FollowingSubscribe for the best X experience: ad-free, post edits, content monetization, Grok AI with higher limits, video downloads, long posts, X Pro, and more.