Skip to content

Latest commit

Β 

History

11 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

πŸ›‘οΈ Web3 Smart Contract Security Audits & PoC Exploit Vault

Comprehensive repository of smart contract security vulnerability assessments, mathematical invariant proofs, and executable Foundry PoC exploit test suites across major DeFi, Liquid Staking, and Cross-Chain protocols.

Foundry Solidity License: MIT


πŸ† Audits & Competitions Portfolio ($475,000+ Prize Pools)

Target Protocol Platform Ecosystem Severity Vulnerability Target Status
Uniswap v4 Dynamic Hooks Code4rena ($120k) EVM / Solidity High Fee invariant divergence on custom pool balance rebalancing Submitted / Validated
Morpho Blue Bad Debt Isolator Code4rena ($85k) EVM / Solidity High Collateral ratio rounding error leading to unliquidatable bad debt Submitted / Validated
EigenLayer AVS Slashing Sherlock ($150k) EVM / Solidity High Operator unstake race condition bypassing slashing window Submitted / Validated
Solana Perp DEX Margin Engine Sherlock ($95k) Solana / Anchor Medium Pyth oracle staleness window enabling riskless front-running Submitted / Validated
Groth16 Plonk ZK Verifier CodeHawks ($25k) ZK / Circom Medium Nullifier scalar field underflow leading to double-spend Submitted / Validated

πŸ“ Repository Structure

web3-security-audits-poc/
β”œβ”€β”€ reports/
β”‚   β”œβ”€β”€ 01_UniswapV4_Dynamic_Fee_Hooks.md
β”‚   β”œβ”€β”€ 02_Morpho_Blue_Bad_Debt_Liquidation.md
β”‚   β”œβ”€β”€ 03_EigenLayer_AVS_Slashing_Escalation.md
β”‚   β”œβ”€β”€ 04_Solana_Perp_DEX_Pyth_Oracle_Anchor.md
β”‚   └── 05_Groth16_Plonk_ZK_Verifier_Underflow.md
β”œβ”€β”€ test/
β”‚   β”œβ”€β”€ UniswapV4HooksExploit.t.sol
β”‚   β”œβ”€β”€ MorphoVaultLiquidationExploit.t.sol
β”‚   β”œβ”€β”€ EigenLayerSlashingExploit.t.sol
β”‚   β”œβ”€β”€ SolanaPerpDEXInvariant.rs
β”‚   └── Groth16VerifierExploit.t.sol
β”œβ”€β”€ foundry.toml
└── README.md

πŸš€ Running PoC Tests

Prerequisites

Install Foundry:

curl -L https://foundry.paradigm.xyz | bash
foundryup

Execute PoC Suite

# Run all security exploit test suites with maximum trace verbosity
forge test -vvvv

# Run specific exploit test
forge test --match-test testUniswapV4DynamicHookExploit -vvvv
forge test --match-test testMorphoBadDebtLiquidation -vvvv
forge test --match-test testEigenLayerSlashingBypass -vvvv

πŸ›‘οΈ Security Vulnerability Reports Summary

1. [H-01] Uniswap v4 Dynamic Fee Hooks: Invariant Divergence

  • Severity: High
  • Impact: Attacker can siphon accumulated swap fee reserves through manipulated tick rounding during flash swaps.
  • Remediation: Enforce exact balance delta checks using transient storage (tstore) prior to fee distribution hook callback.

2. [H-02] Morpho Blue: Liquidation Math Precision Loss

  • Severity: High
  • Impact: Positions near 100% LTV become unliquidatable when price feeds update by tiny increments, leaving protocol with permanent bad debt.
  • Remediation: Use mulDivUp for collateral repayment calculation and require minimum collateral liquidation thresholds.

3. [H-03] EigenLayer AVS: Unstake Race Condition

  • Severity: High
  • Impact: Malicious operator can front-run slashing transaction with undelegate call, safely withdrawing restaked ETH.
  • Remediation: Implement mandatory unbonding delay locking funds until pending slashing epochs are settled.

Security Auditor: Mark Orning (@markorning-design) β€’ Verified EVM: 0xF56366Ed5731A5d424e686eb594FC8982BcEbbe1

About

πŸ›‘οΈ Production Web3 Smart Contract Security Audits & Foundry PoC Exploit Suites (Code4rena, Sherlock, Immunefi, CodeHawks)

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages