https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

BowTiedWardens

Security Researcher

Contact Me

High

5

Total

Medium

18

Total

$21.40K

Total Earnings

#368 All Time

15x

Payouts

silver

1x

2nd Places

bronze

2x

3rd Places

regular

3x

Top 10

All

Code4rena

Jul '22

Fractional v2 contest

Fractional v2 contest

213.57 USDC • 2 total findings • Code4rena • BowTiedWardens

#46

high

Steal NFTs from a Vault, and ETH + Fractional tokens from users.

medium

Use of `payable.transfer()` may lock user funds

Jun '22

Putty contest

Putty contest

223.38 USDC • 3 total findings • Code4rena • BowTiedWardens

#35

medium

`fillOrder()` and `exercise()` may lock Ether sent to the contract, forever

medium

Putty position tokens may be minted to non ERC721 receivers

medium

`fee` can change without the consent of users

Nibbl contest

Nibbl contest

234.87 USDC • Code4rena • BowTiedWardens

#15

Yieldy contest

Yieldy contest

1,623.06 USDC • 5 total findings • Code4rena • BowTiedWardens

#11

high

`Staking.sol#stake()` DoS by staking 1 wei for the recipient when `warmUpPeriod > 0`

medium

No way to set CURVE_POOL approval after setting new curve pool address

medium

Arbitrage on `stake()`

medium

`_storeRebase()` is called with the wrong parameters

medium

Functions in the `BatchRequests` contract revert for removed contract addresses

Illuminate contest

Illuminate contest

680.88 USDC • Code4rena • BowTiedWardens

#21

Nested Finance contest

Nested Finance contest

104.6 USDC • Code4rena • BowTiedWardens

#14

Infinity NFT Marketplace contest

Infinity NFT Marketplace contest

264.63 USDC • 2 total findings • Code4rena • BowTiedWardens

#30

medium

Malicious governance can use `updateWethTranferGas` to steal WETH from buyers

medium

Protocol fee rate can be arbitrarily modified by the owner and the new rate will apply to all existing orders

Connext Amarok contest

Connext Amarok contest

1,639.1 USDC • Code4rena • BowTiedWardens

#13

May '22

Backd Tokenomics contest

Backd Tokenomics contest

453.22 USDC • Code4rena • BowTiedWardens

#17

Aura Finance contest

Aura Finance contest

1,879.89 USDC • 1 total finding • Code4rena • BowTiedWardens

#14

medium

Users may lose rewards to other users if rewards are given as fee-on-transfer tokens

Cally contest

Cally contest

231.31 USDC • 2 total findings • Code4rena • BowTiedWardens

#21

medium

Owner can set the feeRate to be greater than 100% and cause all future calls to `exercise` to revert

medium

Vault is Not Compatible with Fee Tokens and Vaults with Such Tokens Could Be Exploited

Alchemix contest

Alchemix contest

706.87 DAI • Code4rena • BowTiedWardens

#12

Forgotten Runes Warrior Guild contest

Forgotten Runes Warrior Guild contest

2,133.85 USDC • 4 total findings • Code4rena • BowTiedWardens

silver

medium

The owner can mint all of the NFTs.

medium

Contract may not have enough fund to cover refund

medium

Many unbounded and under-constrained variables in the system can lead to unfair price or DoS

medium

Critical variables shouldn't be changed after they are set

bunker.finance contest

bunker.finance contest

5,076.8 USDC • 1 total finding • Code4rena • BowTiedWardens

bronze

medium

`call()` should be used instead of `transfer()` on an `address payable`

Apr '22

AbraNFT contest

AbraNFT contest

5,930.51 MIM • 3 total findings • Code4rena • BowTiedWardens

bronze

high

Avoidance of Liquidation Via Malicious Oracle

high

Critical Oracle Manipulation Risk by Lender

high

Lender is able to seize the collateral by changing the loan parameters