Reproduced Exploit
THORWallet — MergeTgt has no deposit cap vs TGT_TO_EXCHANGE — late claimers stuck
MergeTgt has no deposit cap vs TGT_TO_EXCHANGE — late claimers stuck. Harm demonstrated: Over-subscribed TGT deposits leave late claimers unable to redeem TITN.
Chain
Other
Category
untagged
Date
Feb 2025
Source
AuditVault
EVM Playground
Source-level debugger — step opcodes and Solidity in sync
The attack is replayed in an in-browser EVM preloaded with the exact dumped fork state. The execution tree shows every call; step by Solidity line or by opcode across all depths — source, Stack, Memory, Storage, Balances (native / ERC-20 / NFT), Transient storage and Return value stay in sync. Click a tree node, opcode, or source line to jump. No backend, no live RPC.
Source & credit. Reproduction of a public audit finding curated by AuditVault — the original finding: 55396-h-1-mergetgt-has-no-handling-if-tgttoexchange-is-exceeded-du. Standalone Foundry PoC and full write-up: 55396-h-1-mergetgt-has-no-handling-if-tgttoexchange-is-exceeded-du_exp in the
evm-hack-registrymirror.
Vulnerability classes: integer-bounds, known-pattern
Reproduction: self-contained Foundry PoC (only
forge-std) — no fork, no RPC. Full trace: output.txt. PoC: test/55396-h-1-mergetgt-has-no-handling-if-tgttoexchange-is-exceeded-du_exp.sol.
Key info#
| Impact | HIGH — Over-subscribed TGT deposits leave late claimers unable to redeem TITN |
| Protocol | THORWallet |
| Vulnerable code | MergeTgt (see @> in synthetic) |
| Finding | Code4rena · #55396 |
| Report | https://code4rena.com/reports/2025-02-thorwallet |
| Source | AuditVault |
| Status | Audit finding — reproduced as a standalone local PoC |
| Compiler | ^0.8.24 |
TL;DR#
MergeTgt has no deposit cap vs TGT_TO_EXCHANGE — late claimers stuck. Harm demonstrated: Over-subscribed TGT deposits leave late claimers unable to redeem TITN.
The vulnerable code#
See test/55396-h-1-mergetgt-has-no-handling-if-tgttoexchange-is-exceeded-du.sol — the blamed line is marked // @> VULN.
Root cause#
See the synthetic header comment and the AuditVault finding for the full root-cause write-up. The Playground preserves the vulnerable line verbatim and asserts the concrete harm in Exploit.run().
Attack walkthrough#
- Deploy the reduced vulnerable system (CREATE order: MockERC20(TGT), MockERC20(TITN), MergeTgt, UserActor1, UserActor2).
- Seed the preconditions from the finding (approvals, balances, whitelist).
- Execute the attack path; the
@>line runs. require(...)asserts the harm.
Diagrams#
Impact#
Over-subscribed TGT deposits leave late claimers unable to redeem TITN
Taxonomy#
- integer-bounds, known-pattern
Sources#
- AuditVault finding
- Code4rena report
- Reduced from:
code-423n4/2025-02-thorwallet contracts/MergeTgt.sol onTokenTransfer
Sources & further analysis#
Reproductions & code
- Standalone PoC + full trace: 55396-h-1-mergetgt-has-no-handling-if-tgttoexchange-is-exceeded-du_exp (evm-hack-registry mirror).
- AuditVault finding: 55396-h-1-mergetgt-has-no-handling-if-tgttoexchange-is-exceeded-du.
Alerts & third-party analyses
These dashboards index community alerts tweets, post-mortems, and independent write-ups. Reach them through the protocol name above to cross-check this reproduction against other analyses.