Hi @Rhovian and the Veda-Labs development team,
I am opening this issue to bring an urgent production risk to your attention regarding the live Ink deployments (BalancedUSDC / BoostedUSDC).
I recently submitted a critical vulnerability disclosure via Immunefi (Report #82838). The Immunefi triage team automatically closed the submission based on a strict, literal parsing of a rule exclusion regarding totalSupply() == 0 lifecycle states. However, because the automated triage process focused solely on the initial trigger condition, it completely bypassed the catastrophic, permanent residual impact left on the live architecture: a permanent, unrecoverable exchange rate corruption (Denial of Service via ZeroShares reverts).
Out of an abundance of caution and a commitment to responsible disclosure, I wanted to ensure your engineering team is aware of this so the live deployments can be protected. This finding builds directly on the state-mismatch mechanics noted in Certora finding I-01, but provides the definitive impact analysis and a runnable exploit path demonstrating full protocol degradation.
How to review:
You can access the complete technical write-up and a fully functional, fork-free Foundry PoC directly under the "Closed" tab in your Immunefi dashboard for Report #82838. I have also reached out to Rhovian via X DM with additional high-level context.
Please let me know via Immunefi or a secure channel if you have any issues accessing the report or running the PoC.
Thank you
Hi @Rhovian and the Veda-Labs development team,
I am opening this issue to bring an urgent production risk to your attention regarding the live Ink deployments (BalancedUSDC / BoostedUSDC).
I recently submitted a critical vulnerability disclosure via Immunefi (Report #82838). The Immunefi triage team automatically closed the submission based on a strict, literal parsing of a rule exclusion regarding totalSupply() == 0 lifecycle states. However, because the automated triage process focused solely on the initial trigger condition, it completely bypassed the catastrophic, permanent residual impact left on the live architecture: a permanent, unrecoverable exchange rate corruption (Denial of Service via ZeroShares reverts).
Out of an abundance of caution and a commitment to responsible disclosure, I wanted to ensure your engineering team is aware of this so the live deployments can be protected. This finding builds directly on the state-mismatch mechanics noted in Certora finding I-01, but provides the definitive impact analysis and a runnable exploit path demonstrating full protocol degradation.
How to review:
You can access the complete technical write-up and a fully functional, fork-free Foundry PoC directly under the "Closed" tab in your Immunefi dashboard for Report #82838. I have also reached out to Rhovian via X DM with additional high-level context.
Please let me know via Immunefi or a secure channel if you have any issues accessing the report or running the PoC.
Thank you