https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_6.png

pynschon

Security Researcher

Contact Me

High

7

Total

Medium

2

Total

$319.00

Total Earnings

#1531 All Time

5x

Payouts

bronze

1x

3rd Places

regular

1x

Top 10

regular

2x

Top 25

All

Sherlock

Code4rena

Mar '24

RadicalxChange

RadicalxChange

1.18 USDC • 1 total finding • Sherlock • pynschon

bronze

high

The highest bidder can get auctioned the NFT for free by canceling their bid and closing the auction.

Amphor

Amphor

194.58 USDC • 1 total finding • Sherlock • pynschon

#11

high

Calling `claimDeposit` after `requestDeposit` in the current epoch will lead the user to lose access to their deposits.

Revert Lend

Revert Lend

92.11 USDC • 1 total finding • Code4rena • pynschon

#48

medium

Wrong global lending limit check in `_deposit` function

Feb '24

Althea Liquid Infrastructure

Althea Liquid Infrastructure

7.18 USDC • 1 total finding • Code4rena • pynschon

#34

high

Holders array can be manipulated by transferring or burning with amount 0, stealing rewards or bricking certain functions

AI Arena

AI Arena

24.2 USDC • 5 total findings • Code4rena • pynschon

#105

high

A locked fighter can be transferred; leads to game server unable to commit transactions, and unstoppable fighters

high

Since you can reroll with a different fighterType than the NFT you own, you can reroll bypassing maxRerollsAllowed and reroll attributes based on a different fighterType

high

Fighters cannot be minted after the initial generation due to uninitialized `numElements` mapping

high

Non-transferable `GameItems` can be transferred with `GameItems::safeBatchTransferFrom(...)`

medium

Minter / Staker / Spender roles can never be revoked`..,