s/gakonstSMART CONTRACT SECURITY•22h
2
votes
119
seen
Firelight Finance bug could deny valid claims despite funded vault
A one-second timing bug in Firelight Finance could have left valid cover claims unpaid even while the vault still held enough funds. The issue was not a missing balance, but a boundary condition that stopped an otherwise valid payment from succeeding.
Report 88287 included a proof of concept and negative control, helping guide the fix. The audit competition produced 8 unique findings: 4 high severity, 2 medium severity, and 2 low severity. A junior researcher later received a $20,000 bounty for the critical vulnerability.
Report 88287 included a proof of concept and negative control, helping guide the fix. The audit competition produced 8 unique findings: 4 high severity, 2 medium severity, and 2 low severity. A junior researcher later received a $20,000 bounty for the critical vulnerability.
Timeline3
1d
Immunefi announced the Firelight Finance audit competition results.
1d
Immunefi identified Report 88287 as the competition's Most Valuable Finding, involving the one-second claims-payment boundary condition.
22h
Immunefi reported that a junior researcher received a $20,000 bounty for a critical blockchain vulnerability from the competition.
1 comment
22h