https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

PapaPitufo

Security Researcher

High

2

Solo

2

Total

Medium

1

Solo

4

Total

$71.63K

Total Earnings

#119 All Time

1x

Payouts

gold

1x

1st Places

regular

1x

Top 10

regular

1x

Top 25

All

Sherlock

Sep '24

MorphL2

MorphL2

71,629.76 USDC • 6 total findings • Sherlock • PapaPitufo

gold

high

Attacker can freeze chain and steal challenge deposits using fake `prevStateRoot`

high

Sequencer will be underpaid because of incorrect `commitScalar`

medium

Any sequencer can finalize arbitrary L2 blocks by committing during a challenge period

medium

Sequencer can avoid being slashed for invalid batch

medium

L1 re-org can cause valid challenge to be lost

medium

`Rollup.sol` cannot split batches across blobs, allowing inexpensive block stuffing