reentrancy-simple-dao.sol
VSS-20260923-PU1OJH8E · generated Sep 23, 2026, 1:49 PM
Verdict is derived from severity counts via the same deterministic formula every VegaSec report uses. reentrancy-simple-dao.sol was scanned from pasted source. This is static-analysis triage, not a certification or formal audit attestation.
PDF artifact
Queued artifact pipeline · not blocking on the scan
No PDF artifact has been requested for this report yet. The HTML report and the Markdown export already carry the full disclaimer and limitations inline. PDF synthesis is a queued artifact, not part of the scan path.
Status endpoint
GET /report/solidity/VSS-20260923-PU1OJH8E/export.pdf
Solidity evidence report
16 audit findings
Severity distribution
Executive summary
- 16 findings surfaced (0 critical, 2 high, 0 medium, 0 low, 14 informational).
- HIGH · Reentrancy in PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60): (Collect) — exploitability medium.
- HIGH · LogFile (reentrancy-simple-dao.sol#73-97) contract sets array length with a user-controlled value: (LogFile) — exploitability medium.
- Automated static analysis only. A human operator review has not been attached to this report.
- highReentrancyConfidence: mediumExploitability: mediumDetector: slither
Reentrancy in PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60):
Evidence
Reentrancy in PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60): External calls: - msg.sender.call.value(_am)() (reentrancy-simple-dao.sol#54) State variables written after the call(s): - balances[msg.sender] -= _am (reentrancy-simple-dao.sol#56) PERSONAL_BANK.balances (reentrancy-simple-dao.sol#11) can be used in cross function reentrancies: - PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60) - PERSONAL_BANK.Deposit() (reentrancy-simple-dao.sol#39-45) - PERSONAL_BANK.balances (reentrancy-simple-dao.sol#11)
Exploitability notes
Medium-confidence detection; manual review required before relying on the finding either way.
Remediation
Apply the checks-effects-interactions pattern. State writes must happen before external calls, and consider OpenZeppelin's ReentrancyGuard for high-risk entry points.
- highGas / DoSConfidence: mediumExploitability: mediumDetector: slither
LogFile (reentrancy-simple-dao.sol#73-97) contract sets array length with a user-controlled value:
Evidence
LogFile (reentrancy-simple-dao.sol#73-97) contract sets array length with a user-controlled value: - History.push(LastMsg) (reentrancy-simple-dao.sol#94)
Exploitability notes
Medium-confidence detection; manual review required before relying on the finding either way.
Remediation
Cap loop bounds, paginate iteration, and ensure no user can grow a state structure the contract must traverse to make progress.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Version constraint ^0.4.19 contains known severe issues (https://solidity.readthedocs.io/en/latest/bugs.html)
Evidence
Version constraint ^0.4.19 contains known severe issues (https://solidity.readthedocs.io/en/latest/bugs.html) - DirtyBytesArrayToStorage - ABIDecodeTwoDimensionalArrayMemory - KeccakCaching - EmptyByteArrayCopy - DynamicArrayCleanup - ImplicitConstructorCallvalueCheck - TupleAssignmentMultiStackSlotComponents - MemoryArrayCreationOverflow - privateCanBeOverridden - SignedArrayStorageCopy - ABIEncoderV2StorageArrayWithMultiSlotElement - DynamicConstructorArgumentsClippedABIV2 - UninitializedFunctionPointerInConstructor_0.4.x - IncorrectEventSignatureInLibraries_0.4.x - ABIEncoderV2PackedStorage_0.4.x - ExpExponentCleanup - EventStructWrongData - NestedArrayFunctionCallDecoder. It is used by: - ^0.4.19 (reentrancy-simple-dao.sol#7)
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Contract PERSONAL_BANK (reentrancy-simple-dao.sol#9-69) is not in CapWords
Evidence
Contract PERSONAL_BANK (reentrancy-simple-dao.sol#9-69) is not in CapWords
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Variable PERSONAL_BANK.MinSum (reentrancy-simple-dao.sol#13) is not in mixedCase
Evidence
Variable PERSONAL_BANK.MinSum (reentrancy-simple-dao.sol#13) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Variable PERSONAL_BANK.Log (reentrancy-simple-dao.sol#15) is not in mixedCase
Evidence
Variable PERSONAL_BANK.Log (reentrancy-simple-dao.sol#15) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Parameter PERSONAL_BANK.SetMinSum(uint256)._val (reentrancy-simple-dao.sol#19) is not in mixedCase
Evidence
Parameter PERSONAL_BANK.SetMinSum(uint256)._val (reentrancy-simple-dao.sol#19) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Parameter PERSONAL_BANK.SetLogFile(address)._log (reentrancy-simple-dao.sol#26) is not in mixedCase
Evidence
Parameter PERSONAL_BANK.SetLogFile(address)._log (reentrancy-simple-dao.sol#26) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Function PERSONAL_BANK.Initialized() (reentrancy-simple-dao.sol#33-37) is not in mixedCase
Evidence
Function PERSONAL_BANK.Initialized() (reentrancy-simple-dao.sol#33-37) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Function PERSONAL_BANK.Deposit() (reentrancy-simple-dao.sol#39-45) is not in mixedCase
Evidence
Function PERSONAL_BANK.Deposit() (reentrancy-simple-dao.sol#39-45) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalUnchecked callConfidence: highExploitability: lowDetector: slither
Low level call in PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60):
Evidence
Low level call in PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60): - msg.sender.call.value(_am)() (reentrancy-simple-dao.sol#54)
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Check the boolean return of low-level call/delegatecall/send and revert on failure with a descriptive reason string.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Function PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60) is not in mixedCase
Evidence
Function PERSONAL_BANK.Collect(uint256) (reentrancy-simple-dao.sol#47-60) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Variable LogFile.History (reentrancy-simple-dao.sol#83) is not in mixedCase
Evidence
Variable LogFile.History (reentrancy-simple-dao.sol#83) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Variable LogFile.LastMsg (reentrancy-simple-dao.sol#85) is not in mixedCase
Evidence
Variable LogFile.LastMsg (reentrancy-simple-dao.sol#85) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
AddMessage(address,uint256,string) should be declared external:
Evidence
AddMessage(address,uint256,string) should be declared external: - LogFile.AddMessage(address,uint256,string) (reentrancy-simple-dao.sol#87-95)
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
- informationalLogicConfidence: highExploitability: lowDetector: slither
Parameter LogFile.AddMessage(address,uint256,string)._adr (reentrancy-simple-dao.sol#87) is not in mixedCase
Evidence
Parameter LogFile.AddMessage(address,uint256,string)._adr (reentrancy-simple-dao.sol#87) is not in mixedCase
Exploitability notes
Informational signal; not directly exploitable without additional context.
Remediation
Re-derive the business rule by hand, write a property-based test that fails on the current path, and only then fix the implementation.
Exploit reasoning
Reference-grade reasoning tied to evidence
- be17209907e972ae71cf307d0c8f86aa638fc3afdac4946592499d4cdf419cf0 · reentrancyhighConfidence: low
Conditions point at the exploit but at least one precondition needs operator confirmation.
Preconditions
- External call to an untrusted address before the contract's own state is updated
- Contract or callback path reachable from the external caller
- No nonReentrant guard or equivalent on the entry-point function
Action
Attacker contract receives control during the external call and re-enters the original function before the original state write completes, repeating the state-changing side effect.
Impact
Duplicated withdrawals, double-spend on accounting balances, or out-of-order updates to invariants the function relies on.
False-positive caveats
- The external call may be to a known, trusted contract whose behavior is provable.
- The function may be guarded indirectly by a flag or external lock not visible to the analyzer.
Remediation checklist
- Apply checks-effects-interactions: update internal state before any external call.
- Add a nonReentrant guard on the entry-point function.
- Where feasible, pull-payment instead of push-payment on user balances.
- 4d245ca7eee0a399a1e98c2dc82ccd992096daa414a997a27a6a499524ff3048 · gas-doshighConfidence: low
Conditions point at the exploit but at least one precondition needs operator confirmation.
Preconditions
- Loop over an unbounded data structure controlled by external input
- Single attacker-controlled entry that grows the data structure
Action
Attacker grows the data structure until the loop consumes more gas than the block can hold, blocking the function for everyone.
Impact
Permanent denial of service on critical functions (withdrawals, claim, settle).
False-positive caveats
- The loop may be bounded by other invariants the analyzer cannot prove.
- Pagination or pull-based design may mitigate the issue at a higher layer.
Remediation checklist
- Replace the unbounded loop with a pull-based or paginated pattern.
- Cap the data structure growth at the entry point with a documented limit.
- Add a stress test asserting the loop terminates under adversarial input.
Audit pipeline
Audit cockpit
Honest stage-by-stage view of what VegaSec ran against this contract. Automated stages do not replace a human operator review.
Audit intake
Passed320ms replay1:49 PMNormalize the submitted contract target and confirm it can enter the Solidity audit lane.
Source acquisition
Passed1.4s replay1:49 PMResolve pasted source or verified explorer source without treating malformed input as demo data.
Toolchain validation
Passed2.3s replay1:49 PMConfirm the configured static analyzers can run and produce parseable output.
Static analysis
Passed16 findings8.8s replay1:49 PMRun static analyzers against the sandboxed source and collect raw detector evidence.
Finding normalization
Passed16 findings1.1s replay1:49 PMDedupe detectors, classify vulnerability classes and compute severity-weighted risk.
Exploitability review
Partial16 findings1.9s replay1:49 PMFrame automated findings with conservative exploitability and limitation notes.
- Automated exploitability review is conservative and does not replace a manual exploitability assessment.
Remediation draft
Partial16 findings1.5s replay1:49 PMPrepare remediation-oriented evidence for the shareable report artifact.
- Remediation notes are generated from detector evidence and require project-specific engineering review.
Operator review
Blocked0ms replay1:49 PMRecord whether a human operator artifact exists before buyer escalation.
- No operator review artifact is attached to this automated scan.
- Human operator review has not been attached to this automated scan yet.
Finalization
Partial16 findings620ms replay1:49 PMPublish the automated report artifact or explain why the scan failed closed.
Artifact: Automated Solidity report · solidity-2f746d702f766567
- Final report is an automated static-analysis artifact; no operator review artifact is attached.
How to read this report
Score, confidence, ranking: four moving parts, no hand-tuning.
Generated Sep 23, 2026, 1:49 PM · Solidity · reentrancy-simple-dao.sol
Score bands
0-19
AVOID-style triage
Multiple high or critical findings, low source confidence, or unverified context. Public action should pause until a Private Review or a re-scan with better evidence.
20-49
High caution
Notable findings or thin evidence. Worth a Private Review before relying on the artifact.
50-69
Watch
Mixed signals: some evidence, some gaps. Re-scan after material changes to the target.
70-89
Clear surface (automated) · this report
No critical or high findings via static analysis. Not a safety claim: human review is still recommended for diligence work.
90-100
Strong surface (automated)
No critical or high findings, verified source, and high source confidence. Not a safety claim: human review is still recommended for diligence work.
- Score
- Deterministic 0-100 derived from severity counts. Same formula across every report. Lower means more risk.
- Confidence
- Separate axis. Measures how much VegaSec trusts the input data. Low confidence pushes the verdict toward UNKNOWN; the two are never collapsed into one number.
- Ranking / percentile
- Only meaningful within the eligible Trust Index set. Shown on /trust-index when the eligible pool is large enough. Today the public index is a controlled preview.
Private Review is separate
A paid Private Review does not raise the public score on this report. Public score reflects public-source evidence only. Private Review adds operator attestation and a confidential memo, never a score bump.