https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/151ae1c4-332d-4179-b53e-78df39707f01.png

BowTiedOriole

Security Researcher

Just a bird

Contact Me

High

6

Total

Medium

10

Total

$3.02K

Total Earnings

#894 All Time

8x

Payouts

silver

1x

2nd Places

regular

3x

Top 10

regular

6x

Top 25

All

Sherlock

Code4rena

Apr '24

Exactly Protocol

Exactly Protocol

289.48 USDC • 1 total finding • Sherlock • BowTiedOriole

#11

medium

Unassigned earnings in matured pools will not be included in `totalAssets()` calculation

Mar '24

Revert Lend

Revert Lend

48.75 USDC • 1 total finding • Code4rena • BowTiedOriole

#55

medium

Users can lend and borrow above allowed limitations

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

332.01 USDC • 3 total findings • Code4rena • BowTiedOriole

#8

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

medium

`LiquidInfrastructureERC20.sol` disapproved holders keep part of the supply, diluting approved holders revenue.

medium

Withdrawal from NFTs can be temporarily blocked

Jan '24

Curves

Curves

1,594.54 USDC • 8 total findings • Code4rena • BowTiedOriole

#7

high

Unrestricted claiming of fees due to missing balance updates in `FeeSplitter`

high

Unauthorized Access to setCurves Function

medium

Protocol and referral fee would be permanently stuck in the Curves contract when selling a token

medium

Selling will be bricked if all other tokens are withdrawn to ERC20 token

medium

A subject creator within a single block can claim holder fees without holding due to unprotected reentrancy path

medium

onBalanceChange causes previously unclaimed rewards to be cleared

medium

Curves::_buyCurvesToken(), Excess of Eth received is not refunded back to the user.

medium

Theft of holder fees when `holderFeePercent` was positive and is set to zero

Dec '23

Revolution Protocol

Revolution Protocol

296.99 USDC • 1 total finding • Code4rena • BowTiedOriole

#23

high

Malicious delegatees can block delegators from redelegating and from sending their NFTs

May '23

DODO Margin Trading

DODO Margin Trading

116.10 USDC • 1 total finding • Sherlock • BowTiedOriole

silver

high

All tokens can be stolen from MarginTrading due to unsafe executeOperation

Apr '23

JOJO Exchange

JOJO Exchange

316.20 USDC • 1 total finding • Sherlock • BowTiedOriole

#26

high

GeneralRepay makes generic call allowing approved tokens to be stolen

Mar '23

Neo Tokyo contest

Neo Tokyo contest

29.67 USDC • Code4rena • BowTiedOriole

#21