https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_4.png

betweenETHlines

Security Researcher

Contact Me

High

2

Total

Medium

8

Total

$2.66K

Total Earnings

#930 All Time

4x

Payouts

regular

1x

Top 10

regular

2x

Top 25

regular

4x

Top 50

All

Code4rena

Jan '23

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

54.6 USDC • 2 total findings • Code4rena • betweenETHlines

#41

medium

Possible scenario for Signature Replay Attack

medium

DOS risk if enough tokens are minted in Quest.claim can lead, at least, to transaction fee lost

Ondo Finance contest

Ondo Finance contest

36.24 USDC • Code4rena • betweenETHlines

#19

Biconomy - Smart Contract Wallet contest

Biconomy - Smart Contract Wallet contest

185.85 USDC • 3 total findings • Code4rena • betweenETHlines

#38

high

Attacker can gain control of counterfactual wallet

medium

SmartAccount.sol is intended to be upgradable but inherits from contracts that contain storage and no gaps

medium

methods used by EntryPoint has `onlyOwner` modifier

Dec '22

GoGoPool contest

GoGoPool contest

2,383.63 USDC • 5 total findings • Code4rena • betweenETHlines

#7

high

AVAX Assigned High Water is updated incorrectly

medium

Cancellation of minipool may skip MinipoolCancelMoratoriumSeconds checking if it was cancelled before

medium

State Transition: Minipools can be created using other operator's AVAX deposit via recreateMinipool

medium

`requireNextActiveMultisig` will always return the first enabled multisig which increases the probability of stuck minipools

medium

Coding logic of the contract upgrading renders upgrading contracts impractical