Skip to content

[SECURITY] Precision Loss in Elastic Supply Mechanism - Responsible Disclosure #2856

@ljapptest-art

Description

@ljapptest-art

Summary

I discovered a precision loss vulnerability in OUSD elastic supply accounting system during my security research.

Key Findings

  1. Small holders (100 OUSD) lose ~99 wei per rebase cycle
  2. Extreme case: 1 wei holders receive 0 yield completely
  3. 93% of rebase events (28/30 tested) cause precision loss
  4. Accumulated dust: 746,700 wei lost in invariant testing

Impact

This affects small holders disproportionately, causing fund loss over time.

PoC Available

I have a complete Foundry test suite demonstrating the issue with 5 passing tests. Please contact me at ljapptest@gmail.com for the full PoC code.

Severity

Medium - Fund loss for users, but requires specific conditions.


Please move this to a private security advisory if appropriate. I am available to provide full technical details and PoC code.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions