fund-loss

2 articles
Sort: New Top Best
clear filter
0
vulnerability

Brahma.Fi's collectFees() function incorrectly charges performance fees without accounting for previous losses, causing users to permanently lose funds as fees are collected on unrealized gains. The vulnerability was rejected by Immunefi despite being a critical accounting flaw that will systematically drain user deposits over time due to market volatility.

Brahma.Fi 0x3c4Fe0db16c9b521480c43856ba3196A9fa50E08 Enso Finance Immunefi
trust-security.xyz · Trust · 4 hours ago · details
0
vulnerability

Brahma.Fi's L2 position handler contains a sign confusion bug in positionInWantToken() that miscalculates position value when the account is underwater, treating negative account values as positive funds. This leads to incorrect share calculations during deposits/withdrawals, fee overcharges, and potential protocol insolvency through user exploitation.

Brahma.Fi PerpV2Controller PerpTradeExecutor Perpetual Protocol Optimism 0x1b6BF7Ab4163f9a7C1D4eCB36299525048083B5e
trust-security.xyz · Trust · 4 hours ago · details