https://sherlock-files.ams3.digitaloceanspaces.com/twitter_images/a141295d-9911-4f61-89b4-41cc814cded4.jpg

sinarette

Security Researcher

watson @sherlockdefi warden @code4rena Stepping into web3 securities

Contact Me

High

13

Total

Medium

10

Total

$5.80K

Total Earnings

#745 All Time

8x

Payouts

regular

3x

Top 10

regular

5x

Top 25

regular

7x

Top 50

All

Sherlock

Code4rena

Jun '23

Symmetrical

Symmetrical

280.62 USDC • 3 total findings • Sherlock • sinarette

#25

high

setSymbolPrice Accepts Outdated Signatures

medium

liquidatePositionsPartyB could be permanently blocked

medium

Fees are not returned in liquidation

Apr '23

Blueberry Update

Blueberry Update

293.01 USDC • 1 total finding • Sherlock • sinarette

#9

high

ShortLongSpell would never work

Teller

Teller

53.06 USDC • 3 total findings • Sherlock • sinarette

#42

high

Collateral amount can be manipulated by anyone

medium

Protocol does not support fee-on-transfer tokens

medium

A loan can be liquidated by the lender, while it's still in the open state

Rubicon v2

Rubicon v2

1,551.13 USDC • 7 total findings • Code4rena • sinarette

#7

high

Reward accounting is incorrect in BathBuddy contract

high

The last borrowed asset will not be collateralized and the user may be liquidated due to insufficient collateral

high

An attacker can steal all tokens of users that use `FeeWrapper`

medium

Fee inclusivity calculations are inaccurate in RubiconMarket

medium

Incorrect fee handling in Position.sol's Market Buy/Sell functions

medium

Cannot close leveraged positions

medium

Calling `Position._marketBuy` and `Position._marketSell` functions that calculate `_fee` by dividing by `10000` can cause incorrect calculations

Mar '23

Asymmetry contest

Asymmetry contest

8.03 USDC • 2 total findings • Code4rena • sinarette

#119

high

An attacker can manipulate the preDepositvePrice to steal from other users.

high

`WstEth` derivative assumes a ~1=1 peg of stETH to ETH

Y2K

Y2K

353.32 USDC • 4 total findings • Sherlock • sinarette

#36

high

Rollover queue index is wrong

high

Rollover minting can be skipped after delisting

medium

Epoch can be started and not started at the same time

medium

Emissions are lost for null epoch

Neo Tokyo contest

Neo Tokyo contest

2,819.69 USDC • 1 total finding • Code4rena • sinarette

#7

high

Updating a pool's total points doesn't affect existing stake positions for rewards calculation

Feb '23

Blueberry

Blueberry

442.57 USDC • 2 total findings • Sherlock • sinarette

#24

high

LP tokens would get lost while closing a position

high

Harvested ICHI tokens are not collected