Monolith Market ·Ethereum
Phantom collateral via fee-on-transfer / deflationary collateral tokens
Confirmed and verified — not currently exploitable on live markets
Contract: 0x6D961c9DCF1AD73566822BA4B087892e3839B849
Summary
Lender.adjust() credits a user's internal collateral ledger with the requested transfer amount, not the amount actually received. Any fee-on-transfer or deflationary collateral token lets a user borrow against an inflated ledger balance.
Root cause
collateralBalances[account] is credited before safeTransferFrom() executes and is never reconciled against the contract's actual token balance anywhere in adjust(), liquidate(), writeOff(), or redeem(). Because the Factory is fully permissionless, an attacker can deploy their own market with a purpose-built fee-on-transfer token as collateral.
Verification
Working Foundry PoC against a forked mainnet state via the real, deployed, permissionless Factory.deploy(): attacker deposited 1000 tokens, contract received 900, ledger was credited the full 1000, attacker minted 700 of the market's coin. Honestly scoped: the two currently-live markets (sINV, XAUt) are not exploitable today since neither collateral token is fee-on-transfer - this is a systemic code-level gap, not an active drain.
Verified against real, live deployed contract state.
Receipt on GitHub