Skip to content

Latest commit

 

History

History

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

README.md

LumosKit Run Report — bsc 0x55856d9f…c50b0c

Deterministic final report assembled from existing LumosKit outputs; this finalize step does not call an agent.

Case overview

  • Chain: bsc (chain_id=56)
  • Tx hash: 0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c
  • Block: 104727184
  • Final quality: partial
  • Product/PoC gate: pass
  • Final-quality basis: poc_and_rca
  • Final-quality reason: Verified economic PoC, but RCA is partial.
  • Elapsed: 867.87s (867869 ms)
  • Finding: Spot-reserve POL flush and LP/hashrate credit accepted attacker-controlled same-transaction pair state

Signal context

  • Protocol claim: Little Boy Plus
  • Detector source: manual-poc-readability-rerun

Pipeline timing

  • Orchestrator wall time: 431.21s (431214 ms)

  • Current stage-duration sum: 867.87s (867869 ms)

Stage Artifact Duration Status
cefg cefg 131.38s (131385 ms) success
localize localize 254 ms success
lift lift 1.86s (1857 ms) success
flow_context flow_context 4.42s (4421 ms) success
enrich enrich 15.51s (15514 ms) success
semantic semantic 4.16s (4160 ms) success
context_pack context_pack 465 ms success
asset_delta asset_delta 233 ms success
poc_sketch poc_sketch 1.57s (1575 ms) success
agent_poc agent_poc 276.79s (276791 ms) success
rca rca 431.21s (431214 ms) success

Reproduction quality

  • PoC status: verified
  • Forge fmt: pass
  • Forge build: pass
  • Forge test: pass
  • Proof kind: economic_proof
  • RCA status: partial / partial
  • RCA confidence: medium

Economic reproduction

  • Basis: incident profit oracle usd
  • Verdict: exact — PoC reproduces 99–101% of incident net loss.
  • Incident net loss: $534.31
  • PoC net reproduced: $364489.25
  • USD ratio: 1.000x

Attack narrative

Attack Flow

Generated by agent_poc from deterministic PoC handoff, verified Foundry execution, and economic reproduction artifacts.

Verification Gate

  • Status: pass
  • Execution status: pass
  • Economic status: pass
  • Proof kind: economic_proof
  • Forge build: pass
  • Forge test: pass

Replay Target

  • Transaction: 0x55856d9fda4c5be5193561c7d775e823c3d6e499da44aab9da963daf61c50b0c
  • Block: 104727184
  • Root call type: CREATE
  • Target/tx.to: unknown
  • Attacker: 0xb26dfe6b6180a30e2a2d9826867cc7e06631825a

Observed Trace Flow

  • Ordered by trace evidence line from full CEFG; use this to place PoC constructor, entry, callback, and fallback bodies.
  • [01] line=269 frame 1 attacker_entry:entry@0x202b…38fb --CREATE--> frame 2 dynamic_instantiation:entry@0x5449…118b [localized_to_localized]
  • [02] line=1492 frame 1 attacker_entry:entry@0x202b…38fb --CALL--> frame 3 dynamic_instantiation:0x5258a367@0x5449…118b [localized_to_localized]
  • [03] line=1827 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --STATICCALL--> frame 4 external:entry@0xbb4c…095c [localized_to_external]
  • [04] line=2401 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --STATICCALL--> frame 5 external:entry@0x55d3…7955 [localized_to_external]
  • [05] line=2942 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --STATICCALL--> frame 6 external:entry@0x55d3…7955 [localized_to_external]
  • [06] line=3544 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --CALL--> frame 7 external:entry@0xbb4c…095c [localized_to_external]
  • [07] line=4078 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --CALL--> frame 8 external:entry@0x55d3…7955 [localized_to_external]
  • [08] line=4877 frame 3 dynamic_instantiation:0x5258a367@0x5449…118b --CALL--> frame 9 external:entry@0x8f73…5d8c [localized_to_external]
  • [09] line=6285 frame 10 external:entry@0x8f73…5d8c --CALL--> frame 12 attacker_callback:onMoolahFlashLoan@0x5449…118b [external_callback_to_localized]
  • PoC hint: implement the target selector/fallback as a callback surface; it is entered by an external protocol frame, not direct user calldata.
  • [10] line=6792 frame 12 attacker_callback:onMoolahFlashLoan@0x5449…118b --CALL--> frame 13 external:entry@0x238a…e6c4 [localized_to_external]
  • [11] line=7003 frame 13 external:entry@0x238a…e6c4 --CALL--> frame 14 attacker_callback:lockAcquired@0x5449…118b [external_callback_to_localized]
  • PoC hint: implement the target selector/fallback as a callback surface; it is entered by an external protocol frame, not direct user calldata.
  • [12] line=7596 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 15 external:entry@0x55d3…7955 [localized_to_external]
  • [13] line=7963 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 16 external:entry@0x238a…e6c4 [localized_to_external]
  • [14] line=9551 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 18 external:entry@0x10ed…024e [localized_to_external]
  • [15] line=11573 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 20 external:entry@0x55d3…7955 [localized_to_external]
  • [16] line=12375 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 21 external:entry@0x00e3…1524 [localized_to_external]
  • [17] line=21728 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 33 external:entry@0x00e3…1524 [localized_to_external]
  • [18] line=22696 frame 14 attacker_callback:lockAcquired@0x5449…118b --STATICCALL--> frame 34 external:entry@0x8888…8888 [localized_to_external]
  • [19] line=23493 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 36 external:entry@0x8888…8888 [localized_to_external]
  • [20] line=37898 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 48 external:entry@0x55d3…7955 [localized_to_external]
  • [21] line=38577 frame 14 attacker_callback:lockAcquired@0x5449…118b --CALL--> frame 49 external:entry@0x00e3…1524 [localized_to_external]

PoC Surfaces

|

… truncated in final report; see source artifact for full text.

Multi-leg reconciliation

  • Status: pass
  • Basis: poc_selected_beneficial_payout
  • Source: agent_poc.economic_reproduction
  • Selected rows: 1
  • Note: Verified selected gain-family rows are primary for this economic proof; incident drain/loss legs remain available in the incident context.
Source Direction Holder Role Token Delta USD value
poc_selected_beneficial_payout gain 0x515788797914cb663114aeb806b3cfb6096f6d1a storage_contract BNB 605.555786330933864102 $364489.25

Root cause analysis

  • Title: Spot-reserve POL flush and LP/hashrate credit accepted attacker-controlled same-transaction pair state
  • Severity: critical
  • Confidence: medium
  • Violated invariant: POL execution and LP/hashrate credit must not be priced or credited from attacker-controlled same-block spot reserves without independent slippage, TWAP, or authenticated-liquidity bounds.

Final root cause

PolVault.flushPol() / _doFlushPol prices swaps and liquidity additions from current PancakePair reserves without slippage, TWAP, or manipulation bounds. During the Vault lock, the attacker supplied transient LBP/USDT pair balances, invoked the public POL flush, and then LBP/hLBP accounting accepted the resulting pair mint/reserve state as valid LP/hashrate entitlement. This produced a giant Cake-LP mint to the attack child and downstream USDT/WBNB/BNB profit. The exact hLBP reward/emission sub-branch that accounts for the full Little Boy Plus supply expansion is not fully source-mapped in the supplied frames, so the RCA is partial.

Affected contracts

Address Name Role Implementation
0x01c87119a0D1C3730534b8d909eFeB1911b9fdB0 PolVault primary vulnerable contract
0x88886f0fd371Dff856291bAdcEd45922BC888888 LBP LP staging and settlement accounting
0x5e3cbc82D020be91a989Eb747934104E9AB585Fe LBPHashrate hashrate entitlement crediting
0x00e3Ea08fD8cbAD955Ec5D2292Ad637670C31524 PancakePair downstream LP mint and swap accounting

Recommended fixes

  • In PolVault._swapLbpToUsdt and PolVault._addLiquidity, require TWAP/minAmountOut/minLiquidity/slippage bounds or restrict flush to a keeper/router path with precommitted bounds instead of relying on current pair reserves.
  • In LBP._stagePending, LBP._verifyAndSettle, and LBPHashrate.notifyCredit, bind LP/hashrate credit to authenticated and bounded liquidity-add inputs; reject manual pair donations, skim-shaped reserve manipulation, or same-block spot state as sole proof of user entitlement.
  • Patch direction: guard PolVault.sol:258-303 and the LBP/LBPHashrate credit path at LBP.sol:890-1044, LBP.sol:1436-1466, and LBPHashrate.sol:318-379 so attacker-controllable transient reserves cannot determine POL swap output, liquidity sizing, or hashrate credit.

Limitations

  • missing_assumption: the exact hLBP reward/emission sub-branch and source line that accounts for the full Little Boy Plus supply expansion could not be mapped from the supplied frames.
  • source_branch_gap: the artifacts support the manipulated reserve/POL/LP-credit mechanism, but not every internal LBPHashrate reward/emission transition needed for a complete RCA.
  • The RCA therefore identifies the source-backed vulnerable mechanism and patch points but does not claim a complete branch-by-branch proof for the entire token supply expansion.

Artifacts

Artifact Bundle path Status
Bundle index README.md generated
Machine run summary report/run_summary.json generated
Final integrated report report/REPORT.md generated
RCA report/RCA.md included
RCA structured report report/report.json included
PoC poc/PoC.t.sol included
PoC base support poc/Base.sol included
Asset deltas evidence/asset_deltas.json included
Fund flows evidence/fund_flows.json included
Asset delta graph visuals/asset_deltas.png included
Fund-flow graph visuals/fund_flows.png included