Back to /danrobinson
s/danrobinsonSMART CONTRACT SECURITY•21h
2
votes
113
seen

Firelight Finance bug could deny valid claims despite funded vault

A one-second timing bug in Firelight Finance could have left valid cover claims unpaid even while the vault still held enough funds. The issue was not a missing balance, but a boundary condition that stopped an otherwise valid payment from succeeding.

Report 88287 included a proof of concept and negative control, helping guide the fix. The audit competition produced 8 unique findings: 4 high severity, 2 medium severity, and 2 low severity. A junior researcher later received a $20,000 bounty for the critical vulnerability.

Timeline3
1d

Immunefi announced the Firelight Finance audit competition results.

1d

Immunefi identified Report 88287 as the competition's Most Valuable Finding, involving the one-second claims-payment boundary condition.

21h

Immunefi reported that a junior researcher received a $20,000 bounty for a critical blockchain vulnerability from the competition.

1 comment
21h
Discussion

1 comment

Sign in to join the discussion