Skip to content

[SECURITY] Precision Loss in Elastic Supply Mechanism - Responsible Disclosure #2856

@ljapptest-art

Description

@ljapptest-art

Summary

I discovered a precision loss vulnerability in OUSD elastic supply accounting system during my security research.

Key Findings

  1. Small holders (100 OUSD) lose ~99 wei per rebase cycle
  2. Extreme case: 1 wei holders receive 0 yield completely
  3. 93% of rebase events (28/30 tested) cause precision loss
  4. Accumulated dust: 746,700 wei lost in invariant testing

Impact

This affects small holders disproportionately, causing fund loss over time.

PoC Available

I have a complete Foundry test suite demonstrating the issue with 5 passing tests. Please contact me at ljapptest@gmail.com for the full PoC code.

Severity

Medium - Fund loss for users, but requires specific conditions.


Please move this to a private security advisory if appropriate. I am available to provide full technical details and PoC code.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions