Invalid update of voting power (bias and slopeChanges)
The bias variable and the adjustments to slopeChanges did not correctly track the total voting power across vote-escrowed positions, producing inaccurate governance weights and reward distributions.
Description
The voting-power calculations in BalanceLogicLibrary track each lock as a linear decay from initial voting power down to zero at lock expiry, encoded as bias (current value) and slope (rate of decay). Aggregate voting power is updated by adjusting bias and slopeChanges whenever a lock is created, modified, or ends.
The audit identified incorrect updates in this accounting that produced drift between the recorded global voting power and the true sum of individual lock contributions. The drift compounds over time, so governance votes and reward weights stop reflecting actual user holdings.
Impact
- Governance decisions weighted by voting power become inaccurate.
- Reward weights distributed by voting power become unfair.
- The drift is hard to detect without explicit invariant testing.
Recommendation
Fix the bias and slopeChanges update logic so that the aggregate voting power exactly equals the sum of all individual lock contributions at every block. Add invariant tests covering create, increase, split, merge, and expiry transitions.
Composable Security ID: NRL-6c19a5e-H01. Neverland Money: Fixed. Composable Security: Fix verified during retest.