This repository contains security audit findings for the Alchemix V3 project, a lending and synthetic asset protocol. The audit identified 3 vulnerabilities during the security assessment.
(High Severity)
AlchemistV3 repay function incorrectly transfers the full principal amount as fees instead of the calculated fee amount. This critical flaw allows complete drainage of Alchemist reserves through malicious repayment transactions.
- Impact: Complete drainage of protocol reserves leading to total loss of funds
- Root Cause: Incorrect parameter usage in fee transfer function during repayment process
(High Severity)
Collateral misdirection occurs in the _forceRepay function during liquidation processes, causing funds to be sent to incorrect addresses and disrupting the liquidation mechanism.
- Impact: Loss of collateral funds and compromised liquidation system integrity
- Root Cause: Incorrect recipient address calculation in forced repayment logic
(Informational Severity)
Incorrect bad debt assessment and redemption value calculation due to unhandled token decimal discrepancies in the Transmuter contract. Different token decimals cause arithmetic errors in debt calculations.
- Impact: Inaccurate debt calculations leading to protocol insolvency and user fund loss
- Root Cause: Missing decimal normalization in cross-token arithmetic operations
- Total Findings: 3
- High Severity Findings: 2
- Medium Severity Findings: 0
- Low Severity Findings: 0
- Informational Findings: 1