
Audix_hq
@audix_hq
Audix strengthens your security assessment workflow by analyzing smart contract code to identify heuristics and invariants
ID: 1869422606270550016
https://linktr.ee/audix_hq 18-12-2024 16:41:05
82 Tweet
245 Followers
1 Following

๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฏ๐ฑ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Cork Protocol | Cantina ๐ช ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-4 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Slippage protection ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: The early redemption function only validates minimum output for


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฏ๐ฒ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Berachain Beaconkit | Cantina ๐ช ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-01 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Business logic ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: A blockchain validation function incorrectly returns success


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฏ๐ณ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Milky Way | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-03 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Systemic Failures ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: An attacker can create unlimited reward plans for a small fee, causing


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฏ๐ด ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Berachain Beaconkit | Cantina ๐ช ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-02 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Inadequate validation ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Execution engine's AcceptedPayloadStatus error bypasses


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฏ๐ต ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Milky Way | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-04 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Systemic Failures ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: An attacker can halt the entire blockchain by spamming service


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ฌ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Berachain Beaconkit | Cantina ๐ช ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-03 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Business logic ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Genesis deposits have predefined indices (0-85) but the deposit


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ญ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Milky Way | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-05 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Accounting error ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Service delegations store empty bytes instead of actual delegation data,


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ฎ๐ ๐๐ผ๐ป๐๐ฒ๐๐: TermMax | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-01 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Precision Error ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Small annualized interest values get rounded down to zero when calculating


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ฏ๐ ๐๐ผ๐ป๐๐ฒ๐๐: TermMax | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-02 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Accounting error ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: A mapping that tracks bad debt amounts gets overwritten instead of


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ฐ๐ ๐๐ผ๐ป๐๐ฒ๐๐: TermMax | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-03 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Frontrunnig ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: An attacker can front-run a user's borrowing transaction and redirect the


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ฑ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Milky Way | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-06 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Inadequate validation ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: An attacker can halt the blockchain indefinitely by creating many


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ฒ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Berachain Beaconkit | Cantina ๐ช ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-04 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Inadequate validation ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: A malicious block proposer can forge arbitrary deposits


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฌ๐ฐ๐ณ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Napier | @Cantinaxyz ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-01 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Accounting error ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Users can claim disproportionately more external rewards by collecting


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ด ๐ ๐๐ผ๐ป๐๐ฒ๐๐: DESK | Cantina ๐ช ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-01 ๐๐๐ฝ: 0 ๐๐ฎ๐๐ฒ๐ด๐ผ๐ฟ๐: Accounting error ๐ฃ๐ฎ๐๐ผ๐๐: N/A ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: A liquidation system incorrectly applies collateral factors differently to


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฐ๐ต ๐ ๐๐ผ๐ป๐๐ฒ๐๐: SEDA Protocol | SHERLOCK ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-01 ๐๐๐ฝ: 0 ๐ฃ๐ฎ๐๐ผ๐๐: 3,142 ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Attacker can steal 25% of first depositor's funds by inflating share value through repeated


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฑ๐ฌ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Yieldoor | SHERLOCK ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-02 ๐๐๐ฝ: 0 ๐ฃ๐ฎ๐๐ผ๐๐: 3,738 ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Strategy uses inaccurate slot0 tick instead of actual pool price when setting liquidity positions near


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฑ๐ญ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Perennial V2 | SHERLOCK ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-03 ๐๐๐ฝ: 0 ๐ฃ๐ฎ๐๐ผ๐๐: 4,239 ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Attacker exploits guaranteed Intent orders to withdraw collateral before fees are applied, creating


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฑ๐ฎ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Perennial V2 | SHERLOCK ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-03 ๐๐๐ฝ: 0 ๐ฃ๐ฎ๐๐ผ๐๐: 13,422 ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Settlement fees are subtracted twice in global calculations but only once locally, creating


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฑ๐ฏ ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Perennial V2 | SHERLOCK ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-04 ๐๐๐ฝ: 0 ๐ฃ๐ฎ๐๐ผ๐๐: 6,039 ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Expired oracle versions are treated as valid because they inherit previous version's non-zero


๐ ๐๐ผ๐ป๐๐ฒ๐๐ ๐๐๐ด ๐๐ถ๐ด๐ฒ๐๐ - ๐ฃ๐ง๐ฑ๐ฐ๐ ๐๐ผ๐ป๐๐ฒ๐๐: Perennial V2 | SHERLOCK ๐๐ถ๐ป๐ฑ๐ถ๐ป๐ด ๐๐: H-03 ๐๐๐ฝ: 0 ๐ฃ๐ฎ๐๐ผ๐๐: 13,442 ๐๐๐ด ๐ฆ๐๐บ๐บ๐ฎ๐ฟ๐: Empty market updates don't request oracle versions, causing fee and funding calculations to use
