I found a critical vulnerability in the Percolator v16 program.
UpdateAssetLifecycle(Activate) lets any caller set all per-asset
authorities. Confirmed exploited on mainnet
@toly
Details with on-chain proof: https://t.co/D9aUEU2nZ4
@vitobotta@toly I agree, the authority change is only the first-order impact. I've been tracing dependent programs and trust relationships to understand the full extent of what could be affected.
I found a critical vulnerability in the Percolator v16 program.
UpdateAssetLifecycle(Activate) lets any caller set all per-asset
authorities. Confirmed exploited on mainnet
@toly
Details with on-chain proof: https://t.co/D9aUEU2nZ4
Found another bug in Percolator v16.
Composite oracle has no minimum divisor price.
SOL dips to $0.10 → BTC/SOL composite = $1,000,000 (1500× spike). 11 cranks to propagate. All shorts liquidated. Insurance drains.
@toly@dcc_crypto@0xSquid_Sol
Details: https://t.co/7tBSkEotsG
@stakecraft@toly@dcc_crypto@0xSquid_Sol Nobody centrally, each protocol is audited in isolation by their own auditors or internal teams but composite logic across protocols isn’t really owned end to end. That’s why most risk shows up in how systems interact rather than in a single contract
@notacryptor@toly@dcc_crypto@0xSquid_Sol If needed, I can narrow it down to the highest impact vector and share full details privately to the team, appreciate you!
@notacryptor@toly@dcc_crypto@0xSquid_Sol I’m not claiming every issue is critical individually. I grouped them by logic and permissions. If some are low severity, I’m fine with reclassification. Main concern is the permissionless flow enabling unsafe state changes without proper checks. +++
@notacryptor@toly@dcc_crypto@0xSquid_Sol No
Using Claude Code or any AI tool does not matter. What matters is whether the bug is real, reproducible, and impactful. Nobody gets extra bounty points for opening Vim and reading 50,000 lines of code. The key question is whether you can prove the bug and show its impact
@quant_degen@toly A quick, high conviction sign off
Cracking that means any niche community can spin up its own liquid market from day one. That’s the real breakthrough we’re chasing
@quant_degen@toly Spot-style AMM math doesn't copy paste into long tail perps without toxic skew. The real wizardry is building a risk engine that actually protects passive LPs
@quant_degen@toly Users
If a market solves a real need, liquidity follows. The challenge isn't building more markets, it's creating markets people actually want to trade