oot2k

Senior Watson @Sherlock White hat, Security Researcher

Available
5 years experience
Vetted

Programming Languages

SolidityRust

Expertise & Skills

LendingPerpetualsWalletGovernanceL2

Let Us Help You Connect

Our team can assist with project requirements, timeline coordination, and finding the perfect match

Portfolio & Experience

Detailed audit history and technical expertise

AuditPortfolio

About

Oot2k has collaborated with leading security platforms such as Sherlock, Immunefi, and Bailsec to help secure high-profile projects including Aave, 1inch, Symbiotic, and Nouns DAO. They have completed a total of 33 security audits and submitted three rewarded reports through bug bounty platforms. Several of these audits were conducted in collaboration with renowned auditors including thekmj and Shogoki. Their work primarily focuses on decentralized finance (DeFi), with a selection of their most interesting findings highlighted below under Interesting Discoveries.

Live vulnerabilities

CompanyDatePlatformSeverityReport
EUROe Stable coin15.01.2024Live codeLow-
Undisclosed20.12.2023Live codeCritical (13M at risk)-
Ankr10.12.2023ImmunefiLow-

Security Audits and Bug Bounty Contests

Contest / CompanyDatePlatformRankReportTeam
Hydrex Finance04.08.2025SherlockResearcher--
MetaLend Rebalancer05.08.2025SherlockResearcher--
Tree Protocol18.07.2025SoloResearcher--
40acres Update05.07.2025SherlockResearcher--
Symbiotic Middleware SDK28.05.2025Bail SecResearcher--
MetaLend Rebalancer25.05.2025SherlockResearcher--
Based opinion markets19.05.2025SoloResearcher--
Lazy Bear05.05.2025SherlockResearcher--
40acres Update22.04.2025SherlockResearcher--
1Inch17.04.2025SherlockResearcher--
Tree Protocol NFT15.02.2025SoloResearcher--
40acres25.03.2025SherlockResearcher--
Dodo Swap Velo Fork20.03.2025SherlockResearcher--
MetaLend01.02.2025SherlockResearcher--
Parallel Protocol Audit 201.01.2025Bail SecResearcher--
Parallel Protocol Audit11.12.2024Bail SecPeer Auditor--
Covalent24.10.2024SherlockFirst-PUSH0
Predict.fun24.10.2024SherlockFirst-PUSH0
Magic Sea24.07.2024SherlockLead-PUSH0
Terrace01.06.2024SherlockFirst-PUSH0
Arcadia Update25.04.2024Sherlock2.LinkPUSH0
Perpetual18.03.2024Sherlock3.LinkPUSH0
Arcadia16.02.2024Sherlock4.LinkPUSH0
Covalent22.01.2024SherlockFirstLinkPUSH0
Nouns Builder01.12.2023SherlockFirstLinkSilent Defenders of DeFi
LooksRare04.11.2023Sherlock4.LinkSilent Defenders of DeFi
Perennial V2 Update #1 Judging14.11.2023SherlockFirstLink
Notional V3 Judging15.05.2023Sherlock2.Link

Supporting roles (Judge)

Oot2k has been the lead judge in multiple audit contests. In this role, they are responsible for creating the final report of all issues found during a bug bounty competition. To do this well, judges need a strong understanding of the system or protocol being tested so they can decide which issues should be included in the report for the client.

CompanyDatePlatformRoleReport
Aave v3.301.01.2025SherlockLead Judge-
Symbiotic Middleware SDK22.07.2025SherlockLead Judge-
Nouns DAO01.12.2024SherlockLead Judge-
Dinari06.07.2023SherlockLead JudgeLink
Bond Options Judging08.07.2023SherlockLead JudgeLink

Glossary

Security contests

Cybersecurity contests are conducted on live code or code that is about to be released.
These competitions are mostly open to the public, where anyone can submit potential vulnerabilities to the development team behind the codebase.
Contests are a great form of audit because more people are looking at the code.

Judge

A judge on a bug bounty platform is someone who reviews security reports submitted by participants, verifies whether the issues are valid, and decides their severity and relevance. They ensure only accurate, impactful findings are included in the final results for the client.