Noon (USN) ·Ethereum
MinterHandlerV2 uncollateralized self-mint
Verified with working PoC
Contract: 0xB91b361ebE4022Bb62dF0651bDD09b21209ac058
Summary
mint()'s zero-amount guard and 2%-band collateral/usnAmount ratio check are both gated behind order.user != msg.sender, so any address holding MINTER_ROLE that is also a whitelisted user can self-mint an arbitrary usnAmount with collateralAmount = 0.
Root cause
Falsifies the invariant 'USN minted via MinterHandlerV2.mint() is always backed by proportional collateral' - both safety checks are skipped entirely for the self-mint case.
Verification
Confirmed live, not hypothetical: the address holding MINTER_ROLE, DEFAULT_ADMIN_ROLE, and whitelistedUsers simultaneously on the real, currently-active MinterHandlerV2 was identified on-chain. Passing mainnet-fork Foundry test using a fresh test-controlled EOA granted the identical real role.
Verified against real, live deployed contract state.
Receipt on GitHub