https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/151ae1c4-332d-4179-b53e-78df39707f01.png

BowTiedOriole

Security Researcher

Just a bird

Contact Me

High

9

Total

Medium

14

Total

$4.89K

Total Earnings

#887 All Time

10x

Payouts

silver

1x

2nd Places

regular

4x

Top 10

regular

7x

Top 25

All

Sherlock

Code4rena

Aug '25

GTE Perps and Launchpad

GTE Perps and Launchpad

278.02 USDC • 3 total findings • Code4rena • BowTiedOriole

#53

high

`GTELaunchpadV2Pair` permits minting LP tokens for free when there are non-zero accumulated launch pad fees

high

Attacker can drain funds from `GTELaunchPadV2Pair` using `swap`

medium

User can prevent anyone from receiving rewards

Feb '25

Virtuals Protocol

Virtuals Protocol

1,585.1 USDC • 4 total findings • Code4rena • BowTiedOriole

#4

high

Anybody can control a user's delegate by calling `AgentVeToken.stake()` with 1 wei

medium

Division in `Bonding.sol._openTradingOnUniswap()` results in an incorrect lpSupply, higher vaultSupply, and dust AgentTokens getting locked in FPair

medium

Score in `AgentDAO` is not an accurate measure and can be artificially inflated by spamming proposals

medium

Missing Slippage Protection On Buy And Sell

Apr '24

Exactly Protocol

Exactly Protocol

289.48 USDC • 1 total finding • Sherlock • BowTiedOriole

#11

medium

Unassigned earnings in matured pools will not be included in `totalAssets()` calculation

Mar '24

Revert Lend

Revert Lend

48.75 USDC • 1 total finding • Code4rena • BowTiedOriole

#55

medium

Users can lend and borrow above allowed limitations

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

332.01 USDC • 3 total findings • Code4rena • BowTiedOriole

#8

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

medium

`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.

medium

Withdrawal from NFTs can be temporarily blocked

Jan '24

Curves

Curves

1,594.54 USDC • 8 total findings • Code4rena • BowTiedOriole

#7

high

Unrestricted claiming of fees due to missing balance updates in `FeeSplitter`

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

Selling will be bricked if all other tokens are withdrawn to ERC20 token

medium

A subject creator within a single block can claim holder fees without holding due to unprotected reentrancy path

medium

onBalanceChange causes previously unclaimed rewards to be cleared

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

medium

Theft of holder fees when `holderFeePercent` was positive and is set to zero

Dec '23

Revolution Protocol

Revolution Protocol

296.99 USDC • 1 total finding • Code4rena • BowTiedOriole

#23

high

Malicious delegatees can block delegators from redelegating and from sending their NFTs

May '23

DODO Margin Trading

DODO Margin Trading

116.10 USDC • 1 total finding • Sherlock • BowTiedOriole

silver

high

All tokens can be stolen from MarginTrading due to unsafe executeOperation

Apr '23

JOJO Exchange

JOJO Exchange

316.20 USDC • 1 total finding • Sherlock • BowTiedOriole

#26

high

GeneralRepay makes generic call allowing approved tokens to be stolen

Mar '23

Neo Tokyo contest

Neo Tokyo contest

29.67 USDC • Code4rena • BowTiedOriole

#21