bug-bounty487
google307
xss300
microsoft254
facebook222
rce192
exploit161
apple147
malware140
cve129
account-takeover113
bragging-post110
privilege-escalation88
csrf86
authentication-bypass71
stored-xss66
phishing61
writeup59
reflected-xss59
dos58
browser57
supply-chain55
access-control52
input-validation49
web-security49
react48
reverse-engineering48
defi48
ssrf48
smart-contract47
cross-site-scripting46
open-source46
cloudflare46
ethereum44
oauth44
sql-injection43
lfi42
aws41
web340
web-application38
docker38
ctf37
race-condition37
api-security36
burp-suite36
node35
ai-agents35
pentest34
smart-contract-vulnerability33
information-disclosure33
0
6/10
vulnerability
A sign confusion bug in Brahma's PerpV2Controller misinterprets negative accountValue (indicating underwater positions) as positive funds, causing incorrect share calculations during deposits/withdrawals and enabling protocol insolvency through fund extraction.
sign-confusion
accounting-error
defi
perpetual-protocol
vault-exploit
solvent-risk
negative-value-handling
perp-v2
share-calculation-bug
Brahma.Fi
PerpV2Controller
PerpTradeExecutor
Perpetual Protocol
ClearingHouse