https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_5.png

0xMirce

Security Researcher

Contact Me

High

4

Total

Medium

6

Total

$1.41K

Total Earnings

#1341 All Time

5x

Payouts

regular

1x

Top 25

regular

3x

Top 50

All

Code4rena

Dec '25

Panoptic: Next Core

Panoptic: Next Core

1.75 USDC • 2 total findings • Code4rena • 0xMirce

#32

high

BuilderWallet `init()` is unprotected/re-initializable, enabling takeover and theft of builder fees

medium

`RiskEngine::_getRequiredCollateralAtTickSinglePosition()` Fails to Accumulate Credits Across Multiple Legs, Leading to Potential Erroneous Liquidations

Jul '23

PoolTogether

PoolTogether

168.19 USDC • 2 total findings • Code4rena • 0xMirce

#46

high

`Vault.mintYieldFee` FUNCTION CAN BE CALLED BY ANYONE TO MINT `Vault Shares` TO ANY RECIPIENT ADDRESS

medium

Attacker can frontrun deployVault to deploy at the same address

Mar '23

Asymmetry contest

Asymmetry contest

33.34 USDC • 2 total findings • Code4rena • 0xMirce

#88

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

medium

Missing derivative limit and deposit availability checks will revert the whole `stake()` function

Jan '23

Popcorn contest

Popcorn contest

1,178.59 USDC • 4 total findings • Code4rena • 0xMirce

#19

high

Any user can drain the entire reward fund in MultiRewardStaking due to incorrect calculation of `supplierDelta`

medium

DOS any Staking contract with Arithmetic Overflow

medium

Vault creator can't change feeRecipient after deployment

medium

`MultiRewardStaking.changeRewardSpeed()` breaks the distribution

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

26.84 USDC • Code4rena • 0xMirce

#64