Skip to content

docs(security): clarity-audit on flashstack-core + v3 pools -- F-9 not fixed in v3 successors - #84

Merged
mattglory merged 1 commit into
mainfrom
audit-core-v3-pools
Oct 3, 2026
Merged

mattglory merged 1 commit into
mainfrom
audit-core-v3-pools

Conversation

@mattglory

Copy link
Copy Markdown
Owner

Summary

Fresh clarity-audit pass (aibtcdev/skills framework) over flashstack-core, flashstack-pool-v3, flashstack-stx-pool-v3, and flashstack-sbtc-pool-v3. Follow-on to the v2-pools audit pushed directly to main earlier today (docs/security/CLARITY_AUDIT_V2_POOLS.md) -- opening this one as a proper PR instead.

Headline finding (Critical): flashstack-stx-pool-v3 and flashstack-sbtc-pool-v3 -- the documented successor contracts to the two F-9-vulnerable live v2 pools -- do not fix F-9. Confirmed by direct read: neither has a reentrancy lock on deposit; both are structurally identical to the vulnerable v2 pools' deposit(). If F-9's real fix gets scoped starting from these two files without this being flagged, the result ships the same bug under a new name.

The fix already exists one file over: flashstack-pool-v3 (the generic multi-asset pool, a separate contract) has a per-asset asset-locked reentrancy guard (its own F1 fix, 2026-08-25) that's the exact mechanism to port into both single-asset successors.

Also audited and found clean: flashstack-pool-v3 itself (already through two review passes) and flashstack-core (gen-1, superseded, one informational note on its single-step admin).

Test plan

  • Documentation only, no code changes -- no tests to run.
  • Whoever scopes F-9's real fix should read V3-A before starting.

🤖 Generated with Claude Code

Critical finding: flashstack-stx-pool-v3 and flashstack-sbtc-pool-v3 --
the documented successor contracts to the F-9-vulnerable live v2 pools
-- do not fix F-9. Neither has a reentrancy lock on deposit; both are
structurally identical to the vulnerable v2 pools' deposit() path.
flashstack-pool-v3 already has the right fix pattern (per-asset
asset-locked guard, its own F1 fix) to port into both.

Also covers flashstack-pool-v3 (clean, two prior review passes) and
flashstack-core (gen-1, superseded, one informational note).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
web Ready Ready Preview Oct 2, 2026 2:36pm UTC

Request Review

@unixwhisperer unixwhisperer left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Independently verified, not just read the description:

  • flashstack-stx-pool-v3.clar:94-119 (deposit) and flashstack-sbtc-pool-v3.clar:88-110 (deposit): confirmed directly, no reentrancy guard on either — no check-and-set against any lock var/map before the balance read and transfer.
  • Same two files' flash-loan (stx-pool-v3.clar:153 on): confirmed no guard there either.
  • flashstack-pool-v3.clar's asset-locked pattern (deposit :276-278, withdraw :331-332, flash-loan :365-366): confirmed present, check-first/set-true/reset-false-at-end, exactly as described — this is the pattern to port.

V3-A's severity and recommendation are correct. Agree with holding off on a fresh simnet PoC here — it would just re-run the existing F-9 PoC against byte-identical deposit() logic, not add information.

Approving. Flashstack-ajv.4.9 is already rewritten against this finding (port the guard into both files' three entry points, decide withdraw's lock deliberately rather than copying blindly) — that's the next task.

@mattglory
mattglory merged commit e66b3c5 into main Oct 3, 2026
7 checks passed
@mattglory
mattglory deleted the audit-core-v3-pools branch October 3, 2026 15:04

This branch was successfully deployed

1 active deployment
Preview — e394ac3e Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants