⛏ Marasoon Mining Rigs — 6-Cylinder Engine
▶ 23/30 routes confirmed · target 30/30
MAR-001
coinbase/cb-mpc
Schnorr 2P partial signature oracle
✓ FILED
9.1
CRITICAL
CVSS: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
🏆 H1 #3756133 · coinbase bounty
MAX BOUNTY: TBD
⚙ 6-CYLINDER ENGINE · ALL 6 ROUTES
1
info-theoretic
✅ PROVED
2
game-theoretic
✅ PROVED
3
UC-security
✅ PROVED
4
nonce-reuse
✅ PROVED
5
code-invariant
✅ PROVED
6
API-undefined
✅ PROVED
mar001_route1: 1>0 → 1 constraint leaked
x1 = (O_a−O_b)·(e_a−e_b)⁻¹
Lean4: ZombieFloorProofs.lean · 0 sorry · 29 theorems
Lean4: ZombieFloorProofs.lean · 0 sorry · 29 theorems
MAR-002
EigenLayer
Slashing cascade AllocationManager
◎ DRAFT
9.0
CRITICAL
MAX BOUNTY: $500K
⚙ 6-CYLINDER ENGINE · 4/6 CONFIRMED
1
info-theoretic
✅ PROVED
2
game-theoretic
✅ PROVED
3
UC-security
✅ PROVED
4
code-invariant
✅ PROVED
5
nonce-reuse
⚠ NEEDED
→ fork test vs mainnet required
→ Alchemy: eth-mainnet.g.alchemy.com
→ Alchemy: eth-mainnet.g.alchemy.com
6
API-undefined
⚠ NEEDED
→ mainnet confirm required
MAR-003
Symbiotic
Vault withdrawal race condition
◎ DRAFT
8.5
HIGH
MAX BOUNTY: $250K
⚙ 6-CYLINDER ENGINE · 5/6 CONFIRMED
1
info-theoretic
✅ PROVED
2
game-theoretic
✅ PROVED
3
code-invariant
⚠ NEEDED
→ on-chain state invariant verification
4
nonce-reuse
✅ PROVED
5
UC-security
✅ PROVED
6
API-undefined
✅ PROVED
MAR-004
Chainlink CCIP
Stale price oracle settlement
◎ DRAFT
7.5
HIGH
MAX BOUNTY: $50K
⚙ 6-CYLINDER ENGINE · 4/6 CONFIRMED
1
info-theoretic
⚠ NEEDED
→ entropy bound on stale price data
2
game-theoretic
⚠ NEEDED
→ rational adversary EV calculation
3
UC-security
✅ PROVED
4
code-invariant
✅ PROVED
5
nonce-reuse
✅ PROVED
6
API-undefined
✅ PROVED
MAR-005
Pendle Finance
PT/YT price manipulation
◎ DRAFT
8.0
HIGH
MAX BOUNTY: $100K
⚙ 6-CYLINDER ENGINE · 4/6 CONFIRMED
1
info-theoretic
✅ PROVED
2
game-theoretic
✅ PROVED
3
code-invariant
⚠ NEEDED
→ AMM invariant proof PT/YT price floor
4
nonce-reuse
✅ PROVED
5
UC-security
✅ PROVED
6
API-undefined
⚠ NEEDED
→ undocumented YT redemption edge case
🔴 CB001 · coinbase pve_ac
Zombie Floor Vulnerability · CRITICAL ~$50K · pending CLO gate
⚡ CLO-GATE
zombie floor root: q_forged = q_forged := rfl
hermitian discriminant: H = H† (self-adjoint verification floor)
oracle leak: x1 = (O_a−O_b)·(e_a−e_b)⁻¹
sigs[] undocumented state on abort path → deterministic oracle ✓
hermitian discriminant: H = H† (self-adjoint verification floor)
oracle leak: x1 = (O_a−O_b)·(e_a−e_b)⁻¹
sigs[] undocumented state on abort path → deterministic oracle ✓
Routes:
6/6 confirmed
· Marasoon-6 standard achieved
⛔ Blocked: CLO sign-off required (msclo MAAT · Amani Joffe review)