https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/1c46914b-a3b3-4cf7-925d-20274cb9c66c.jpg

bhilare_

Security Researcher

Nothing... just Web3

Contact Me

High

10

Total

Medium

3

Total

$186.00

Total Earnings

#1685 All Time

5x

Payouts

regular

1x

Top 25

regular

2x

Top 50

All

Sherlock

Code4rena

Aug '24

Chakra

Chakra

2.46 USDT • 4 total findings • Code4rena • bhilare_

#53

high

There is no refund mechanism in `ChakraSettlement.processCrossChainCallback` or `ChakraSettlementHandler.receive_cross_chain_callback` function

high

Anyone can manipulate user nonce (nonce_manager) in settlement contract

high

SettlementSignatureVerifier is missing check for duplicate validator signatures

medium

Does not check if to_chain and to_handler is whitelisted in cross_chain_erc20_settlement

Apr '24

DYAD

DYAD

41.38 USDC • 4 total findings • Code4rena • bhilare_

#71

high

Design flaw and mismanagement in vault licensing leads to double counting in collateral ratios and positions collateralized entirely with kerosine

high

User can get their Kerosene stuck because of an invalid check on withdraw

high

Unable to withdraw Kerosene from `vaultmanagerv2::withdraw` as it expects a `vault.oracle()` method which is missing in Kerosene vaults

medium

No incentive to liquidate small positions could result in protocol going underwater

Mar '24

Axis Finance

Axis Finance

71.41 USDC • 2 total findings • Sherlock • bhilare_

#25

high

While creating an Auction, routing information in `lotRouting` is never stored for new `lotId`, instead is overwritten for lotId = 0.

medium

A partially filled capacity lot winner can cause settling of lot to always REVERT if blacklisted.

Feb '24

Rio Network

Rio Network

5.57 USDC • 1 total finding • Sherlock • bhilare_

#31

high

If an `epoch` is settled from EigenLayer, the epoch is not been updated/increased after settlement.

AI Arena

AI Arena

65.66 USDC • 2 total findings • Code4rena • bhilare_

#78

high

Players have complete freedom to customize the fighter NFT when calling `redeemMintPass` and can redeem fighters of types Dendroid and with rare attributes

high

Player can mint more fighter NFTs during claim of rewards by leveraging reentrancy on the `claimRewards() function `