Normal behavior: while moderator re-flagging is still allowed, a corrected good-faith CORRUPTED outcome should settle from the same economic pool that existed before the mistaken flag.
I observed that sweepUnclaimedBonus() can move accounted totalBonus to recoveryAddress without setting claimsStarted when riskWindowStart == 0. Since claimsStarted remains false, the moderator can still correct the outcome to good-faith CORRUPTED, but the later bounty snapshot uses the reduced totalBonus. The attacker bounty is therefore computed without the sponsor bonus that was already swept.
The issue is not that bonus sweeping exists. The issue is that sweeping accounted totalBonus changes the economics of a later valid correction while the protocol still considers the correction window open.
Likelihood:
This occurs when a pool has no observed risk window (riskWindowStart == 0), the moderator first flags SURVIVED, and sweepUnclaimedBonus() is called before the moderator corrects to good-faith CORRUPTED.
The path uses normal protocol functions. No non-standard token behavior, reentrancy, callback, or privileged sweeper is required.
Impact:
A valid good-faith attacker can be underpaid by the entire sponsor bonus.
The bonus is diverted to recoveryAddress, while the later corrected bountyEntitlement includes only staked principal.
Create this file:
Run:
Observed output:
The PoC proves that:
SURVIVED is initially flagged while claimsStarted == false.
sweepUnclaimedBonus() transfers the accounted 50e18 bonus to recoveryAddress.
The correction window remains open because claimsStarted is still false.
A later good-faith CORRUPTED correction snapshots totalBonus == 0.
The attacker receives only 100e18 stake instead of 150e18 stake plus bonus.
Separate dust/donation sweeping from accounted bonus sweeping. Accounted totalBonus should not be swept while moderator correction is still possible unless the sweep itself closes finality.
A stricter fix is to disallow sweeping accounted totalBonus while re-flagging is still possible. Donation/dust-only sweeps can remain non-final because they were never part of totalBonus.
Impact – Medium Up to the entire bonus pool can be routed to the wrong party for good, with no on-chain way to unwind it, and in a stakerless pool the effect is total since bountyEntitlement computes to zero and claimAttackerBounty reverts outright. This impact is definitely not High: the pool stays solvent throughout with no principal ever at risk, and the money ends up at the sponsor's own recoveryAddress, which in most pools means a sponsor recovering a bonus they funded themselves. The whitehat's claim on that bonus also only exists because the moderator changed their mind after the fact. Likelihood – Low Four separate things have to coincide: nobody touches the pool for the whole active-risk window (or there are no stakers to begin with), the moderator flags SURVIVED and later reverses to CORRUPTED, that reversal is good-faith with a named attacker, and a sweep lands between the two flags. The first cuts against staker self-interest, since skipping the poke costs them their entire bonus share, and the second asks the moderator to overturn a scope judgement, which is a bigger deal than the typo fix DESIGN.md #4 offers the window for. The sweep itself I'd treat as near-certain once the rest holds, given it's permissionless and the sponsor has an obvious reason to make the call, but assembling the first three in one pool lifecycle is where this stays rare.
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
View preliminary resultsAppeals are being carefully reviewed by our judges.
The contest is complete and the rewards are being distributed.