All findings

Orvex ·Robinhood Chain

ProtocolToken.sol has no burn() - veORVX early-exit claims permanently revert

High

Verified with working PoC

Contract: 0x18657fF9943FAA5D16C6ea1BC13dd8767984C30E

token standard gapfund lockuser-facing DoS

Summary

VotingEscrowV2_LockLogic._claim() calls token.burn(penaltyAmount) whenever an early exit's penalty is nonzero, but the real deployed ORVX token (ERC20 + ERC20Permit + Ownable2Step only) has no burn() function at all. Any user - no privileged role needed - who locks ORVX in a NON_PERMANENT lock and later tries to exit early, accepting the documented penalty, has the transaction unconditionally revert.

Root cause

A core, advertised exit path calls a token function that was never implemented on the real deployed token. There is no other way to exit a NON_PERMANENT lock before natural expiry, so funds are provably stuck past the user's chosen duration regardless of what penalty they'd accept.

Verification

Fork PoC: funded a fresh user, created a real NON_PERMANENT lock, warped 15 days in with real remaining voting power confirmed on-chain, then showed claim() reverts inside the missing token.burn() call every time.

Verified against real, live deployed contract state.

Receipt on GitHub