Missing minimum transaction amount validation enables dust-attack congestion
Several entry points accepted zero or near-zero transaction amounts. Combined with the protocol's emissions/rewards bookkeeping, this enabled cheap dust-attack patterns that bloat state and consume gas on legitimate users.
Description
Several user-facing entry points (lock, deposit, claim, reward operations) accepted zero or dust-sized amounts without rejecting them. Each such transaction still updated state, emitted events, and contributed to the global accounting. An attacker could submit large volumes of dust transactions to bloat state, increase gas costs on legitimate users, and complicate off-chain indexing.
Impact
- Storage bloat in state-heavy structures.
- Higher gas costs for legitimate users (iteration over user-history arrays).
- Off-chain indexer load and noise in events.
Recommendation
Enforce a minimum transaction amount on user-facing entry points. Reject zero-value transactions outright; reject sub-threshold amounts with a clear error.
Composable Security ID: NRL-6c19a5e-L05. Neverland Money: Fixed. Composable Security: Fix verified during retest.