Reproduced Exploit
H-1: notifyUnsubscribe gas underestimation leaves phantom gauge liquidity
Uniswap unsubscribes while Deli gauge keeps full position liquidity (phantom dilution)
Chain
Other
Category
untagged
Date
Sep 2025
Source
AuditVault
EVM Playground
Source-level debugger — step opcodes and Solidity in sync
The attack is replayed in an in-browser EVM preloaded with the exact dumped fork state. The execution tree shows every call; step by Solidity line or by opcode across all depths — source, Stack, Memory, Storage, Balances (native / ERC-20 / NFT), Transient storage and Return value stay in sync. Click a tree node, opcode, or source line to jump. No backend, no live RPC.
Source & credit. Reproduction of a public audit finding curated by AuditVault — the original finding: 62808-h-1-gas-consumed-in-notifyunsubscribe-is-underestimated-duri. Standalone Foundry PoC and full write-up: 62808-h-1-gas-consumed-in-notifyunsubscribe-is-underestimated-duri_exp in the
evm-hack-registrymirror.
| Field | Value |
|---|---|
| Protocol | BMX Deli Swap |
| Severity | high |
| Source | AuditVault / https://github.com/sherlock-audit/2025-09-bmx-deli-swap-judging |
| Harm | Uniswap unsubscribes while Deli gauge keeps full position liquidity (phantom dilution) |
TL;DR#
Uniswap unsubscribes while Deli gauge keeps full position liquidity (phantom dilution)
Vulnerable code#
See the synthetic reproduction in test/62808-h-1-gas-consumed-in-notifyunsubscribe-is-underestimated-duri.sol — the blamed line is marked // @> VULN.
Root cause#
Faithful reduction of the AuditVault finding. The vulnerable line is preserved so the Playground locator points at the real bug, not scaffolding.
Attack walkthrough#
- Deploy the reduced protocol pieces via the
Exploitconstructor. run()performs the attack end-to-end andrequires the harm.
Diagrams#
Impact#
Uniswap unsubscribes while Deli gauge keeps full position liquidity (phantom dilution)
Taxonomy#
- severity/high
- sector/dex
- platform/auditvault
Sources#
- AuditVault finding: https://github.com/Auditware/AuditVault/blob/main/findings/62808-h-1-gas-consumed-in-notifyunsubscribe-is-underestimated-duri.md
- Original report: https://github.com/sherlock-audit/2025-09-bmx-deli-swap-judging
- Reduced from: sherlock-audit/2025-09-bmx-deli-swap (PositionManagerAdapter/Notifier gas path)
Sources & further analysis#
Reproductions & code
- Standalone PoC + full trace: 62808-h-1-gas-consumed-in-notifyunsubscribe-is-underestimated-duri_exp (evm-hack-registry mirror).
- AuditVault finding: 62808-h-1-gas-consumed-in-notifyunsubscribe-is-underestimated-duri.
Alerts & third-party analyses
These dashboards index community alerts tweets, post-mortems, and independent write-ups. Reach them through the protocol name above to cross-check this reproduction against other analyses.