https://sherlock-files.ams3.digitaloceanspaces.com/profile_images/defaults/default_avatar_2.png

thimthor

Security Researcher

Contact Me

High

4

Total

Medium

2

Total

$292.00

Total Earnings

#1787 All Time

3x

Payouts

regular

3x

Top 25

regular

3x

Top 50

All

Sherlock

Oct '25

Index Fun Order Book

Index Fun Order Book

2.16 USDC • 1 total finding • Sherlock • thimthor

#14

high

Seller pays for buyerFeeRate inside of `MarketController::_executeTokenSwap` instead of buyer

Sep '25

Ammplify

Ammplify

290.19 USDC • 4 total findings • Sherlock • thimthor

#23

high

`FeeWalker::up` will undercalculate `compoundingLiq` by a factor of `key.width()` for all unvisited nodes

high

Inconsistent high tick exclusivity between `WalkerLib::modify` and `PoolWalker::settle` resulting in inconsistent updates and settles

medium

`TimedAdmin` implemented in `Diamond` is broken for `acceptOwnership` resulting in ownership not being able to be transferred

medium

`NFTManager::_generateMetadata` and `NFTManager::_generateSVG` retrieves asset data from NFTManager storage instead of Diamond storage resulting in DoS of `NFTManager::tokenURI` calls

Mar '25

Crestal Network

Crestal Network

0.01 USDC • 1 total finding • Sherlock • thimthor

#12

high

Arbitrary transfer from in public function `Payment::payWithERC20` allows an attacker to steal approved funds