https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_1.png

mookimgo

Security Researcher

Contact Me

High

4

Total

Medium

6

Total

$8.49K

Total Earnings

#634 All Time

6x

Payouts

silver

1x

2nd Places

regular

1x

Top 10

regular

2x

Top 25

All

Code4rena

Jan '23

Popcorn contest

Popcorn contest

758.8 USDC • 2 total findings • Code4rena • mookimgo

#30

high

Attacker can deploys vaults with a malicious Staking contract

medium

Anyone can reset fees to 0 value when Vault is deployed

RabbitHole Quest Protocol contest

RabbitHole Quest Protocol contest

21.29 USDC • 2 total findings • Code4rena • mookimgo

#69

high

Bad implementation in minter access control for `RabbitHoleReceipt` and `RabbitHoleTickets` contracts

medium

DOS risk if enough tokens are minted in Quest.claim can lead, at least, to transaction fee lost

Timeswap contest

Timeswap contest

7,471.3 USDC • 2 total findings • Code4rena • mookimgo

silver

high

TimeswapV2LiquidityToken should not use totalSupply()+1 as tokenId

medium

Burning a `ERC1155Enumerable` token doesn't remove it from the enumeration

Dec '22

GoGoPool contest

GoGoPool contest

21.71 USDC • 1 total finding • Code4rena • mookimgo

#75

medium

Coding logic of the contract upgrading renders upgrading contracts impractical

Forgeries contest

Forgeries contest

110.27 USDC • 1 total finding • Code4rena • mookimgo

#17

medium

Protocol safeguards for time durations are skewed by a factor of 7. Protocol may potentially lock NFT for period of 7 years.

Tigris Trade contest

Tigris Trade contest

110.68 USDC • 2 total findings • Code4rena • mookimgo

#51

high

reentrancy attack during mint() function in Position contract which can lead to removing of the other user's limit orders or stealing contract funds because initId is set low value

medium

Trading will not work on ethereum if USDT is used