fix(F-9): independently prove the sbtc-pool-v2 deposit-reentrancy variant - #86
Merged
Merged
Conversation
…iant flashstack-sbtc-pool-v2 was previously only read directly and judged to share flashstack-stx-pool-v2's deposit-as-repayment vector (ajv.4.8), not independently simnet-proven. Its repayment path goes through a SIP-010 transfer (asserts tx-sender == sender) rather than stx-transfer?, a materially different mechanism worth confirming rather than assuming. Adds a receiver that reenters deposit() from inside a flash-loan callback, funded via as-contract from the loan proceeds, mirroring stx-pool-v2-deposit-reentrancy.test.ts's construction. A control receiver that repays by plain transfer gets zero shares, isolating the effect to the deposit-reentrancy mechanism. FINDINGS_REGISTER.md's F-9 row updated to match.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
… set test-sbtc-pool-v2-receiver-deposit-reentrant.clar is a contracts/test/ file like its already-accepted STX sibling (test-pool-v2-receiver-deposit-reentrant.clar, already in KNOWN_TEST_PATHS), so it shows up in what `clarinet deployments apply --mainnet` would publish from this repo. Reviewed addition, same category as the existing entry -- not a silent list growth.
4 of 5 tasks
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
flashstack-sbtc-pool-v2was previously only read directly and judged to shareflashstack-stx-pool-v2's F-9 deposit-as-repayment vector (Flashstack-ajv.4.8), not independently simnet-proven. Its repayment path goes through a SIP-010transfercall (assertstx-sender == sender) rather thanstx-transfer?— a materially different mechanism, worth confirming rather than assuming it carries over.tests/sbtc-pool-v2-deposit-reentrancy.test.tsand receivercontracts/test/test-sbtc-pool-v2-receiver-deposit-reentrant.clar(registered inClarinet.toml), mirroringstx-pool-v2-deposit-reentrancy.test.ts'sas-contractconstruction.docs/security/FINDINGS_REGISTER.md's F-9 row to record the sBTC pool as confirmed rather than "not yet independently proven."Result
3/3 new tests pass: the loan succeeds via deposit-as-repayment; the receiver contract ends up with shares funded entirely out of the loan proceeds (attacker spends nothing beyond a fee-sized buffer) while the honest LP's value drops; a control honest-repay-by-transfer receiver gets exactly zero shares, isolating the effect to the deposit-reentrancy mechanism and ruling out a harness artifact.
Both live v2 pools remain
paused=true(Matt's existing mitigation, unaffected by this PR) — this is evidence-gathering only, no contract or mitigation change.Test plan
npx vitest run tests/sbtc-pool-v2-deposit-reentrancy.test.ts— 3/3 passnpx vitest run(full suite) — 263 passed, 3 pre-existing skips, 0 failures, no regressions🤖 Generated with Claude Code