All findings

Monolith Market ·Ethereum

Phantom collateral via fee-on-transfer / deflationary collateral tokens

Medium

Confirmed and verified — not currently exploitable on live markets

Contract: 0x6D961c9DCF1AD73566822BA4B087892e3839B849

accountingfee-on-transferpermissionless factory

Summary

Lender.adjust() credits a user's internal collateral ledger with the requested transfer amount, not the amount actually received. Any fee-on-transfer or deflationary collateral token lets a user borrow against an inflated ledger balance.

Root cause

collateralBalances[account] is credited before safeTransferFrom() executes and is never reconciled against the contract's actual token balance anywhere in adjust(), liquidate(), writeOff(), or redeem(). Because the Factory is fully permissionless, an attacker can deploy their own market with a purpose-built fee-on-transfer token as collateral.

Verification

Working Foundry PoC against a forked mainnet state via the real, deployed, permissionless Factory.deploy(): attacker deposited 1000 tokens, contract received 900, ledger was credited the full 1000, attacker minted 700 of the market's coin. Honestly scoped: the two currently-live markets (sINV, XAUt) are not exploitable today since neither collateral token is fee-on-transfer - this is a systemic code-level gap, not an active drain.

Verified against real, live deployed contract state.

Receipt on GitHub