Xiaoming9090
@xiaoming9090
Followers
3K
Following
438
Media
7
Statuses
106
Founding Security Researcher @blackthornxyz | Lead Senior Watson @sherlockdefi | Security Researcher @SpearbitDAO | Portfolio: https://t.co/sg2mgn4ZkM
Joined January 2022
After more than a year of competing in Sherlock, I have finally achieved #1 on the leaderboard. I'm looking forward to competing in more contests, contributing to the security of more protocols, and continuing to learn from the many great auditors out there.
18
6
176
π @allbridge_io Audit Contest Results π Congrats to: 1. @Alicrali333, @EgisSec, @VeerendraVamshi, @X0sauce, @xiaoming9090, BobbyAudit - $700 π₯ 2. 0xloophole, @0xdemonnn, @0xomeiza, @MishkatM80976, Emine, Hurricane, MysteryAuditor, WillyCode20 - $549 π₯ $19,000 rewards β‘οΈ
4
4
29
π @usualmoney Audit Contest Results π Congrats to: 1. @0xSlowbug, @0xlemonaudits, @4mj3x, @demorextess, @dobrevaleri, @drynooo, @hope_silver, @moray5554, @xiaoming9090, Martians - $3,910 π₯ $50,000 rewards β‘οΈ $15.2M+ paid out in rewards.
3
7
57
π @DebitaFinance Audit Contest Results π Congrats to: 1. @xiaoming9090 - 6,610.96 USDCπ₯ 2. @thongtrungtran - 5,913.00 USDCπ₯ @xiaoming9090 made 25,000.00 USDC fixed pay + 6,610.96 USDC from the contest pot! 60,500.00 USDC rewards β‘οΈ $12.8M+ paid out in rewards.
π¨ New contest: Debita Finance V3 @DebitaFinance π¨ Sign up here: https://t.co/98UKzG0dbQ Total Rewards: 62,000 USDC nSLOC: 2325 Lead Senior Watson: @xiaoming9090 Starts Monday, November 11th at 15:00 UTC Check it out!!
1
1
17
Looking forward to securing more protocols at @blackthornxyz!
Introducing xiaoming90, the first founding security researcher of @blackthornxyz. @xiaoming9090's track record speaks for itself. 21 audit contest wins. 18 contests as Lead Senior Watson. Held the #1 spot on Sherlock's leaderboard for many weeks. His background is traditional
5
0
72
π @usualmoney Audit Contest Results π Congrats to: 1. 0xmystery, @0xNirix, @0x_0x37, @KupiaSecurity, @xiaoming9090, @zarkk01, Bigsam, dhank - 4,367.29 USDCπ₯ 2. @niroh30, LZ_security, PeterSR, ke1caM - 3,354.08 USDCπ₯ @xiaoming9090 made 21,500.00 USDC fixed pay + 4,367.29
π¨ New contest: Usual V1 @usualmoney π¨ Sign up here: https://t.co/e3bmoxhSGI Total Rewards: 89,000 USDC nSLOC: 3312 Lead Senior Watson: @xiaoming9090 Starts Tuesday, October 29th at 15:00 UTC Check it out!!
2
5
21
π @symm_io Audit Contest Results π Congrats to: 1. @xiaoming9090 - $15,000.00π₯ @xiaoming9090 made $9,000.00 fixed pay + $15,000.00 from the contest pot! $26,000.00 rewards β‘οΈ $11.8M+ paid out in rewards.
π¨ New contest: SYMMIO v0.8.4 Update Contest @symm_io π¨ Sign up here: https://t.co/4vuOmpx6Wg Total Rewards: 26,000 USDC Previous Scope nSLOC: 5057 Update Scope nSLOC: 723 Lead Senior Watson: @xiaoming9090 Starts Wednesday, October 2nd at 15:00 UTC Check it out!!
1
1
16
Was great working with the @TokemakXYZ team and @xiaoming9090 on this one
Crowd Competition Working @sherlockdefi, Autopilotβs codebase underwent a crowd competition that combined a traditional audit, led by @xiaoming9090 (Lead Watson), with a crowd-sourced approach. Crowd competitions offer a complementary level of scrutiny to the review process.
1
1
7
@sherlockdefi @xiaoming9090 Thank you @sherlockdefi and thank you @xiaoming9090 π€ Great experience and a great Watson.
0
1
3
Crowd Competition Working @sherlockdefi, Autopilotβs codebase underwent a crowd competition that combined a traditional audit, led by @xiaoming9090 (Lead Watson), with a crowd-sourced approach. Crowd competitions offer a complementary level of scrutiny to the review process.
1
1
13
Sherlock tier list revealed. All LSWs are S tier (literally saved hundreds of millions in TVL for Sherlock-audited projects). Jack is not S-tier since he can't become an LSW.
3
2
37
Shoutout to @gjaldon for the right answer. At the time of the post, the stats were: 1. @IAm0x52 with 373 bugs reported 2. @bin2chen with 350 bugs reported 3. @xiaoming9090 with 248 findings (Sherlock only accepts the high and medium severity findings)
Identify the top 3 LSWs with the most findings reported. These top performers have each submitted over 300 valid findings and have been actively participating in contests since 2022. Who do you think they might be?
1
1
18
π @NotionalFinance Audit Contest Results π Congrats to: 1. @xiaoming9090 - $7,000.28π₯ 2. @aiot66 - $5,104.27π₯ 3. @0xnovaman33 - $2,334.95π₯ @xiaoming9090 made $12,500.00 fixed pay + $7,000.28 from the contest pot! $37,500.00 rewards β‘οΈ $9.3M+ paid out in rewards.
π¨ New contest: Notional Leveraged Vaults: Pendle PT and Vault Incentives @NotionalFinance π¨ Sign up here: https://t.co/9bXZuuuItf Total Rewards: 37,500 USDC nSLOC: 1140 Lead Senior Watson: @xiaoming9090 Starts Wednesday, June 26th at 15:00 UTC Check it out!!
1
2
12
I gathered some public data and made a pretty table out of it: π The Hall of Fame of Competitive Auditors π
5
5
87
π @symm_io Audit Contest Results π Congrats to: 1. @xiaoming9090 - $9,714.29π₯ 2. slowfi - $5,298.70π₯ 3. @k_anandk - $1,987.01π₯ @xiaoming9090 made $9,000.00 fixed pay + $9,714.29 from the contest pot! $27,500.00 rewards β‘οΈ $8.9M+ paid out in rewards.
π¨ New contest: SYMMIO v0.83 Update Contest @symm_io π¨ Sign up here: https://t.co/eUjCnamCHT Total Rewards: 27,500 USDC Previous Scope nSLOC: 4072 Update Scope nSLOC: 869 Lead Senior Watson: @xiaoming9090 Starts Monday, June 17th at 15:00 UTC Check it out!!
0
4
8
Sidenote: - For readers who are interested in seeing how the formula works in this scenario, you may refer to https://t.co/qINxDvel27 - For readers who are interested to know how the formula is derived, you may refer to
2
0
14
Good luck, and I hope this helps you earn some High/Medium in your future contests if a similar scenario appears π
2
0
14
(9/9) The correct formula to be used in such a scenario is as follows:
1
0
9
(8/9) The treasury only received 19.6 ETH worth of shares instead of 20 ETH worth of shares, losing approximately 0.4 ETH. Intuitively, minting new two (2) shares for the treasury increases the denominator of the formula while keeping the numerator fixed, thus diluting the share
1
0
5
(7/9) How much are the two (2) shares the treasury received worth now? Ideally, it should be 20 ETH since they are entitled to a 20 ETH fee. Letβs check:
2
0
5