Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2024-0001·input-validation

Decimals not handled by the application frontend, producing exponential session-balance values

Acknowledgedpentestblackboxnestjs
TL;DR

Users could enter long decimal values into the deposit amount; the frontend then rendered an exponential value (e.g., 1e-14) and persisted it into the session balance, creating rounding and display drift between the UI and the backend settlement.

Severity
HIGH
Impact
HIGH
Likelihood
MEDIUM
Method
MManual review
CAT.
Complexity
LOW
Exploitability
MEDIUM
02Section · Description

Description

In allyourbase.virtual.tech a user could manually enter 1.(decimal) numbers in the deposit amount. The frontend then displayed an exponential amount (e.g., 1e-14) for both the virtual and the session balance.

After finishing a session, the virtual balance also updated with exponentials. Since the application relies on blockchain technology, these rounding errors could lead to issues in the calculations, or even just gas griefing, as the backend might not handle decimal values properly.

03Section · Impact

Impact

  • Display drift between the UI's exponential representation and any backend numeric handling.
  • Possible rounding errors in settlement, leading to incorrect win/loss adjustments.
  • Increased risk of gas griefing if the on-chain layer rejects or mis-handles tiny decimal values.
04Section · Recommendation

Recommendation

Validate the deposit amount as a fixed-precision decimal at the input boundary. Reject values below a sensible minimum unit (for example, 1 microUSDT). Display amounts using a fixed-decimal formatter rather than relying on JavaScript's default number formatter, and ensure UI and backend agree on the canonical numeric representation.

All Your Base: Acknowledged. Zealynx: Acknowledged.

F-2024-0001