All findings

Orvex ·Robinhood Chain

oORVX.exerciseVe() unconditionally reverts - same missing-burnFrom root cause, independent entry point

Medium

Verified — second entry point, same root cause

Contract: 0xD47F4D84a68C27906E599f5a0E90F95ff815A8C9

token standard gapbroken core feature

Summary

oORVX's exerciseVe() converts option tokens into a permanent veORVX lock via createLockFor(), which unconditionally calls token.burnFrom() for any PERMANENT lock inside VotingEscrowV2_LockLogic._updateLock(). ORVX has no burnFrom() either, so this documented conversion path is completely non-functional for every holder.

Root cause

Same protocol-wide token-standard gap as the early-exit claim bug, reached through a third independent code path (alongside the blocked max>0 branch of the Minter genesis-mint bug) - every PERMANENT lock creation anywhere in the protocol hits this.

Verification

Fork PoC: wrapped real ORVX into oORVX the normal way (1:1, permissionless), then confirmed exerciseVe() reverts inside createLockFor -> _updateLock -> token.burnFrom() for a real funded holder.

Verified against real, live deployed contract state.

Receipt on GitHub