Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
F-2025-0012·input-validation

Missing minimum transaction amount validation enables dust-attack congestion

FixedlendingmonadveToken
TL;DR

Several entry points accepted zero or near-zero transaction amounts. Combined with the protocol's emissions/rewards bookkeeping, this enabled cheap dust-attack patterns that bloat state and consume gas on legitimate users.

Severity
LOW
Impact
LOW
Likelihood
HIGH
Method
MManual review
CAT.
Complexity
LOW
Exploitability
HIGH
02Section · Description

Description

Several user-facing entry points (lock, deposit, claim, reward operations) accepted zero or dust-sized amounts without rejecting them. Each such transaction still updated state, emitted events, and contributed to the global accounting. An attacker could submit large volumes of dust transactions to bloat state, increase gas costs on legitimate users, and complicate off-chain indexing.

03Section · Impact

Impact

  • Storage bloat in state-heavy structures.
  • Higher gas costs for legitimate users (iteration over user-history arrays).
  • Off-chain indexer load and noise in events.
04Section · Recommendation

Recommendation

Enforce a minimum transaction amount on user-facing entry points. Reject zero-value transactions outright; reject sub-threshold amounts with a clear error.

Composable Security ID: NRL-6c19a5e-L05. Neverland Money: Fixed. Composable Security: Fix verified during retest.

Status
Fixed
Fix commit
816c394500f1
Fix date
2025-08-22
F-2025-0012