Deterministic final report assembled from existing LumosKit outputs; this finalize step does not call an agent.
- Chain: bsc (chain_id=56)
- Tx hash:
0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c - Block: 104727184
- Final quality:
partial - Product/PoC gate:
pass - Final-quality basis:
poc_and_rca - Final-quality reason: Verified economic PoC, but RCA is partial.
- Elapsed: 867.87s (867869 ms)
- Finding: Spot-reserve POL flush and LP/hashrate credit accepted attacker-controlled same-transaction pair state
- Protocol claim: Little Boy Plus
- Detector source: manual-poc-readability-rerun
-
Orchestrator wall time: 431.21s (431214 ms)
-
Current stage-duration sum: 867.87s (867869 ms)
| Stage | Artifact | Duration | Status |
|---|---|---|---|
cefg |
cefg |
131.38s (131385 ms) | success |
localize |
localize |
254 ms | success |
lift |
lift |
1.86s (1857 ms) | success |
flow_context |
flow_context |
4.42s (4421 ms) | success |
enrich |
enrich |
15.51s (15514 ms) | success |
semantic |
semantic |
4.16s (4160 ms) | success |
context_pack |
context_pack |
465 ms | success |
asset_delta |
asset_delta |
233 ms | success |
poc_sketch |
poc_sketch |
1.57s (1575 ms) | success |
agent_poc |
agent_poc |
276.79s (276791 ms) | success |
rca |
rca |
431.21s (431214 ms) | success |
- PoC status:
verified - Forge fmt:
pass - Forge build:
pass - Forge test:
pass - Proof kind:
economic_proof - RCA status:
partial/partial - RCA confidence:
medium
- Basis: incident profit oracle usd
- Verdict: exact — PoC reproduces 99–101% of incident net loss.
- Incident net loss: $534.31
- PoC net reproduced: $364489.25
- USD ratio: 1.000x
Generated by agent_poc from deterministic PoC handoff, verified Foundry execution, and economic reproduction artifacts.
- Status:
pass - Execution status:
pass - Economic status:
pass - Proof kind:
economic_proof - Forge build:
pass - Forge test:
pass
- Transaction:
0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c - Block:
104727184 - Root call type:
CREATE - Target/tx.to:
unknown - Attacker:
0xb26dfe6b6180a30e2a2d9826867cc7e06631825a
- Ordered by trace evidence line from full CEFG; use this to place PoC constructor, entry, callback, and fallback bodies.
- [01] line=269 frame 1 attacker_entry:entry@0x202b…38fb --CREATE--> frame 2 dynamic_instantiation:entry@0x5449…118b [localized_to_localized]
- [02] line=1492 frame 1 attacker_entry:entry@0x202b…38fb --CALL--> frame 3 dynamic_instantiation:0x5258a367@0x5449…118b [localized_to_localized]
- [03] line=1827 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --STATICCALL--> frame 4 external:entry@0xbb4c…095c [localized_to_external]
- [04] line=2401 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --STATICCALL--> frame 5 external:entry@0x55d3…7955 [localized_to_external]
- [05] line=2942 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --STATICCALL--> frame 6 external:entry@0x55d3…7955 [localized_to_external]
- [06] line=3544 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --CALL--> frame 7 external:entry@0xbb4c…095c [localized_to_external]
- [07] line=4078 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --CALL--> frame 8 external:entry@0x55d3…7955 [localized_to_external]
- [08] line=4877 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --CALL--> frame 9 external:entry@0x8f73…5d8c [localized_to_external]
- [09] line=6285 frame 10 external:entry@0x8f73…5d8c --CALL--> frame 12 attacker_callback:onMoolahFlashLoan@0x5449…118b [external_callback_to_localized]
- PoC hint: implement the target selector/fallback as a callback surface; it is entered by an external protocol frame, not direct user calldata.
- [10] line=6792 frame 12 attacker_callback:onMoolahFlashLoan@0x5449…118b --CALL--> frame 13 external:entry@0x238a…e6c4 [localized_to_external]
- [11] line=7003 frame 13 external:entry@0x238a…e6c4 --CALL--> frame 14 attacker_callback:lockAcquired@0x5449…118b [external_callback_to_localized]
- PoC hint: implement the target selector/fallback as a callback surface; it is entered by an external protocol frame, not direct user calldata.
- [12] line=7596 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 15 external:entry@0x55d3…7955 [localized_to_external]
- [13] line=7963 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 16 external:entry@0x238a…e6c4 [localized_to_external]
- [14] line=9551 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 18 external:entry@0x10ed…024e [localized_to_external]
- [15] line=11573 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 20 external:entry@0x55d3…7955 [localized_to_external]
- [16] line=12375 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 21 external:entry@0x00e3…1524 [localized_to_external]
- [17] line=21728 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 33 external:entry@0x00e3…1524 [localized_to_external]
- [18] line=22696 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 34 external:entry@0x8888…8888 [localized_to_external]
- [19] line=23493 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 36 external:entry@0x8888…8888 [localized_to_external]
- [20] line=37898 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 48 external:entry@0x55d3…7955 [localized_to_external]
- [21] line=38577 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 49 external:entry@0x00e3…1524 [localized_to_external]
|
… truncated in final report; see source artifact for full text.
- Status:
pass - Basis:
poc_selected_beneficial_payout - Source:
agent_poc.economic_reproduction - Selected rows: 1
- Note: Verified selected gain-family rows are primary for this economic proof; incident drain/loss legs remain available in the incident context.
| Source | Direction | Holder | Role | Token | Delta | USD value |
|---|---|---|---|---|---|---|
| poc_selected_beneficial_payout | gain | 0x515788797914cb663114aeb806b3cfb6096f6d1a |
storage_contract |
BNB |
605.555786330933864102 | $364489.25 |
- Title: Spot-reserve POL flush and LP/hashrate credit accepted attacker-controlled same-transaction pair state
- Severity:
critical - Confidence:
medium - Violated invariant: POL execution and LP/hashrate credit must not be priced or credited from attacker-controlled same-block spot reserves without independent slippage, TWAP, or authenticated-liquidity bounds.
PolVault.flushPol() / _doFlushPol prices swaps and liquidity additions from current PancakePair reserves without slippage, TWAP, or manipulation bounds. During the Vault lock, the attacker supplied transient LBP/USDT pair balances, invoked the public POL flush, and then LBP/hLBP accounting accepted the resulting pair mint/reserve state as valid LP/hashrate entitlement. This produced a giant Cake-LP mint to the attack child and downstream USDT/WBNB/BNB profit. The exact hLBP reward/emission sub-branch that accounts for the full Little Boy Plus supply expansion is not fully source-mapped in the supplied frames, so the RCA is partial.
| Address | Name | Role | Implementation |
|---|---|---|---|
0x01c87119a0D1C3730534b8d909eFeB1911b9fdB0 |
PolVault |
primary vulnerable contract |
— |
0x88886f0fd371Dff856291bAdcEd45922BC888888 |
LBP |
LP staging and settlement accounting |
— |
0x5e3cbc82D020be91a989Eb747934104E9AB585Fe |
LBPHashrate |
hashrate entitlement crediting |
— |
0x00e3Ea08fD8cbAD955Ec5D2292Ad637670C31524 |
PancakePair |
downstream LP mint and swap accounting |
— |
- In PolVault._swapLbpToUsdt and PolVault._addLiquidity, require TWAP/minAmountOut/minLiquidity/slippage bounds or restrict flush to a keeper/router path with precommitted bounds instead of relying on current pair reserves.
- In LBP._stagePending, LBP._verifyAndSettle, and LBPHashrate.notifyCredit, bind LP/hashrate credit to authenticated and bounded liquidity-add inputs; reject manual pair donations, skim-shaped reserve manipulation, or same-block spot state as sole proof of user entitlement.
- Patch direction: guard PolVault.sol:258-303 and the LBP/LBPHashrate credit path at LBP.sol:890-1044, LBP.sol:1436-1466, and LBPHashrate.sol:318-379 so attacker-controllable transient reserves cannot determine POL swap output, liquidity sizing, or hashrate credit.
- missing_assumption: the exact hLBP reward/emission sub-branch and source line that accounts for the full Little Boy Plus supply expansion could not be mapped from the supplied frames.
- source_branch_gap: the artifacts support the manipulated reserve/POL/LP-credit mechanism, but not every internal LBPHashrate reward/emission transition needed for a complete RCA.
- The RCA therefore identifies the source-backed vulnerable mechanism and patch points but does not claim a complete branch-by-branch proof for the entire token supply expansion.
| Artifact | Bundle path | Status |
|---|---|---|
| Bundle index | README.md |
generated |
| Machine run summary | report/run_summary.json |
generated |
| Final integrated report | report/REPORT.md |
generated |
| RCA | report/RCA.md |
included |
| RCA structured report | report/report.json |
included |
| PoC | poc/PoC.t.sol |
included |
| PoC base support | poc/Base.sol |
included |
| Asset deltas | evidence/asset_deltas.json |
included |
| Fund flows | evidence/fund_flows.json |
included |
| Asset delta graph | visuals/asset_deltas.png |
included |
| Fund-flow graph | visuals/fund_flows.png |
included |