Skip to content

Security Notice: Production Risk & Immunefi Report #82838 Review Request #29

Description

@SimSans

Hi @Rhovian and the Veda-Labs development team,

I am opening this issue to bring an urgent production risk to your attention regarding the live Ink deployments (BalancedUSDC / BoostedUSDC).

I recently submitted a critical vulnerability disclosure via Immunefi (Report #82838). The Immunefi triage team automatically closed the submission based on a strict, literal parsing of a rule exclusion regarding totalSupply() == 0 lifecycle states. However, because the automated triage process focused solely on the initial trigger condition, it completely bypassed the catastrophic, permanent residual impact left on the live architecture: a permanent, unrecoverable exchange rate corruption (Denial of Service via ZeroShares reverts).

Out of an abundance of caution and a commitment to responsible disclosure, I wanted to ensure your engineering team is aware of this so the live deployments can be protected. This finding builds directly on the state-mismatch mechanics noted in Certora finding I-01, but provides the definitive impact analysis and a runnable exploit path demonstrating full protocol degradation.

How to review:
You can access the complete technical write-up and a fully functional, fork-free Foundry PoC directly under the "Closed" tab in your Immunefi dashboard for Report #82838. I have also reached out to Rhovian via X DM with additional high-level context.

Please let me know via Immunefi or a secure channel if you have any issues accessing the report or running the PoC.

Thank you

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions