docs(security): clarity-audit on flashstack-core + v3 pools -- F-9 not fixed in v3 successors - #84
Merged
Merged
Conversation
Critical finding: flashstack-stx-pool-v3 and flashstack-sbtc-pool-v3 -- the documented successor contracts to the F-9-vulnerable live v2 pools -- do not fix F-9. Neither has a reentrancy lock on deposit; both are structurally identical to the vulnerable v2 pools' deposit() path. flashstack-pool-v3 already has the right fix pattern (per-asset asset-locked guard, its own F1 fix) to port into both. Also covers flashstack-pool-v3 (clean, two prior review passes) and flashstack-core (gen-1, superseded, one informational note). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
unixwhisperer
approved these changes
Oct 3, 2026
unixwhisperer
left a comment
Collaborator
There was a problem hiding this comment.
Independently verified, not just read the description:
flashstack-stx-pool-v3.clar:94-119(deposit) andflashstack-sbtc-pool-v3.clar:88-110(deposit): confirmed directly, no reentrancy guard on either — no check-and-set against any lock var/map before the balance read and transfer.- Same two files'
flash-loan(stx-pool-v3.clar:153 on): confirmed no guard there either. flashstack-pool-v3.clar'sasset-lockedpattern (deposit :276-278, withdraw :331-332, flash-loan :365-366): confirmed present, check-first/set-true/reset-false-at-end, exactly as described — this is the pattern to port.
V3-A's severity and recommendation are correct. Agree with holding off on a fresh simnet PoC here — it would just re-run the existing F-9 PoC against byte-identical deposit() logic, not add information.
Approving. Flashstack-ajv.4.9 is already rewritten against this finding (port the guard into both files' three entry points, decide withdraw's lock deliberately rather than copying blindly) — that's the next task.
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fresh clarity-audit pass (aibtcdev/skills framework) over
flashstack-core,flashstack-pool-v3,flashstack-stx-pool-v3, andflashstack-sbtc-pool-v3. Follow-on to the v2-pools audit pushed directly to main earlier today (docs/security/CLARITY_AUDIT_V2_POOLS.md) -- opening this one as a proper PR instead.Headline finding (Critical):
flashstack-stx-pool-v3andflashstack-sbtc-pool-v3-- the documented successor contracts to the two F-9-vulnerable live v2 pools -- do not fix F-9. Confirmed by direct read: neither has a reentrancy lock ondeposit; both are structurally identical to the vulnerable v2 pools'deposit(). If F-9's real fix gets scoped starting from these two files without this being flagged, the result ships the same bug under a new name.The fix already exists one file over:
flashstack-pool-v3(the generic multi-asset pool, a separate contract) has a per-assetasset-lockedreentrancy guard (its own F1 fix, 2026-08-25) that's the exact mechanism to port into both single-asset successors.Also audited and found clean:
flashstack-pool-v3itself (already through two review passes) andflashstack-core(gen-1, superseded, one informational note on its single-step admin).Test plan
🤖 Generated with Claude Code