https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

0xMirce

Security Researcher

Contact Me

High

4

Total

Medium

6

Total

$1.41K

Total Earnings

#1195 All Time

4x

Payouts

regular

1x

Top 25

regular

2x

Top 50

All

Code4rena

Jul '23

PoolTogether

PoolTogether

168.19 USDC • 2 total findings • Code4rena • 0xMirce

#46

high

`Vault.mintYieldFee` FUNCTION CAN BE CALLED BY ANYONE TO MINT `Vault Shares` TO ANY RECIPIENT ADDRESS

medium

Attacker can frontrun deployVault to deploy at the same address

Mar '23

Asymmetry contest

Asymmetry contest

33.34 USDC • 2 total findings • Code4rena • 0xMirce

#88

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

medium

Missing derivative limit and deposit availability checks will revert the whole `stake()` function

Jan '23

Popcorn contest

Popcorn contest

1,178.59 USDC • 4 total findings • Code4rena • 0xMirce

#19

high

Any user can drain the entire reward fund in MultiRewardStaking due to incorrect calculation of `supplierDelta`

medium

DOS any Staking contract with Arithmetic Overflow

medium

Vault creator can't change feeRecipient after deployment

medium

`MultiRewardStaking.changeRewardSpeed()` breaks the distribution

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

26.84 USDC • 2 total findings • Code4rena • 0xMirce

#64

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts

medium

Users may not claim Erc1155 rewards when the Quest has ended