Filed / Active
MAR-002 · cb-mpc PVE-AC
Coinbase · pve_ac skip_verify forged restore · S_rfl
CRITICAL
FILED #3762137
T0/T1
→ view bonsai
Ready to File
MM-005 · DelegationManager Caveat
MetaMask · Caveat non-inheritance · S_delegation
HIGH
READY ★
T1
→ view bonsai
MM-006 · validateDelegation Guard
MetaMask · Guard bypass via decodedPermission · S_delegation
HIGH
READY ★
T1
→ view bonsai
Audit Check Needed
COSMOS-002 · Gov Tally Race
Cosmos SDK · Vote period boundary race condition · S_boundary
CRITICAL
AUDIT CHK
T6
→ view bonsai
TRON-001 · Precision Loss
TRON Stake 2.0 · Java double truncation in bandwidth · S_precision
HIGH
VERIFY ◆
T4
→ view bonsai
Enzyme Blue (Immunefi)
FIND-001/002 · Oracle Staleness
ChainlinkLikeWstethPriceFeed · Round completeness + heartbeat · S_oracle
HIGH ×2
T3/T5
FIND-003 · Approval Wipe
GatedRedemptionQueue · Full approval deleted on partial use · S_conservation
MEDIUM
T1 · AW=14.13
FIND-005 · Multi-Throttle Bypass
SharePriceThrottled · N instances = N×lossTolerance · S_additive
HIGH
T4
$82K – $1.315M
Total addressable · 5 programmes · Day 113
Coinbase: $50K–$1M (filed)
MetaMask: $5K–$50K (ready)
Cosmos: $20K–$200K (audit chk)
TRON DAO: $5K–$50K (verify)
Enzyme: $2K–$15K (immunefi)
Circle: $2K–$15K (parked)