All findings

Orvex ·Robinhood Chain

bveORVX.exerciseVe() calls a function selector that doesn't exist on the real oORVX contract

Medium

Verified with working PoC

Contract: 0xD2190FC5Df4aBDc9Dc4b6804dabe3435B14eb8B3

interface mismatchbroken core feature

Summary

bveORVX's optionToken is statically typed as the 5-argument OptionTokenV3.exerciseVe(uint256,uint256,address,uint256,uint256) (selector 0xa9f6ee33), but the contract actually deployed at that address only implements the simpler 2-argument exerciseVe(uint256,address) (selector 0x9130325d) - two entirely different functions as far as the EVM is concerned.

Root cause

An interface/version mismatch between two of Orvex's own contracts, distinct from the missing-burn bugs found elsewhere - calling a selector the target contract never defined falls through to nothing and reverts every time.

Verification

Fork PoC: directly probed the 5-arg selector against the real deployed optionToken address (confirmed it doesn't exist), then called bveORVX.exerciseVe() the way any real user would (amount=0, isolating the call from needing a real balance) and confirmed it reverts identically.

Verified against real, live deployed contract state.

Receipt on GitHub