position-miscalculation

1 article
sort: new top best
clear filter
0 7/10
vulnerability

Brahma.Fi's L2 position handler miscalculates the value of positions in negative states due to sign confusion in the positionInWantToken() function, where negative account values (indicating underwater accounts rather than short positions) are treated as positive, leading to incorrect share issuance, excess withdrawals, and potential protocol insolvency.

Brahma.Fi PerpV2Controller PerpTradeExecutor Perpetual Protocol Optimism
trust-security.xyz · Trust · 23 hours ago · details