Security Researcher
Web3 Security Researcher | Founding SR @blackthornxyz | TG : https://t.co/xXCYO3LdHa
High
Total
Medium
Solo
Total
Total Earnings
#157 All Time
Payouts
1st Places
2nd Places
Top 10
All
Sherlock
Blackthorn
Code4rena
Cantina
CodeHawks
Immunefi
Feb '25
Collaborative Audit • Blackthorn • sammy
Nov '24
medium
Oct '24
high
high
high
high
high
high
high
medium
medium
Sep '24
high
`L1ReverseCustomGateway.sol::onDropMessage()` will revert, leading to locked ERC20 tokens
medium
Unclaimed sequencer commissions will be lost forever if the sequencer withdraws on L1 or gets slashed on L1
medium
L1 block re-org could cause an honest challenger to lose their `challengeDeposit`
medium
The 255th staker in `L1Staking.sol` can avoid getting slashed and inadvertently cause fund loss to stakers
medium
Batches committed during an on going challenge can avoid being challenged
Aug '24
medium
Jul '24
high
`Tokens` Are Automatically Whitelisted Upon Creation And Binding Even When `_whiteListEnabled == false`
medium
Starknet tokens deposited with use_withdraw_auto can never be withdrawn
medium
Reentrancy attack to make an NFT unbridgeable
low
Upon the transfer of an escrowed NFT from the bridge to the user on StarkNet, the escrow status remains unaltered, failing to be reset
low
Incorrect function signatures in `_callBaseUri` break `baseURI` functionality
Jun '24
May '24
medium
Apr '24
high
`collectionReferrerShare` is routed to the wrong referrer in `FeeManager.sol`
high
A user can mint tokens of `tokenId` at a much lower cost due to incorrect fee collection logic in `Edition.sol`
medium
`Edition.sol::mintBatch()` will always revert for `tokenIds_.length` greater than 1
medium
`EDITION_MINTER_ROLE` is not configurable as `grantRoles()` cannot be called in `Edition.sol`
medium
The mint fees is sent to the old creator even after updating the creator with `transferWork()`
medium
Updating the fee strategy using `setFeeStrategy()` does not update the royalty info, resulting in inconsistent royalty information
Mar '24