Security Researcher
High
Total
Medium
Total Earnings
#850 All Time
Payouts
Top 25
Top 50
All
Code4rena
Nov '21
1,955.04 USDC • 3 total findings • Code4rena • ScopeLift
#18
high
Possible incentive theft through the arbitraryCall() function
Wrong calculation of excess depositToken allows stream creator to retrieve `depositTokenFlashloanFeeAmount`, which may cause fund loss to users
medium
arbitraryCall() can get blocked by an attacker
2,139.8 USDC • 3 total findings • Code4rena • ScopeLift
#11
_notSameBlock() can be circumvented in bondToAccount()
Permissions - return values not checked when sending ETH
AbstractRewardMine - Re-entrancy attack during withdrawal