Urgent.News

What's breaking now, across thousands of outlets.

Tech

Protocol Upgrade Compatibility Review: Sky Lending

Protocol Upgrade Compatibility Review: Sky Lending Target Protocol : Sky Lending (TVL: $5883.8M) Protocol Upgrade Compatibility Review – Sky Lending TVL: ≈ $5.88 B (Ethereum + L2s) Date of Review: 4 Oct 2026 Prepared by: [Your Name], Senior DeFi Security Researcher & Smart‑Contract Auditor 1. Executive Summary Sky Lending is a high‑value, cross‑chain lending platform that aggregates liquidity…

Sky Lending is a cross-chain lending platform with a TVL of approximately $5.88 billion, split between Ethereum L1 and L2 roll-ups like Optimism, Arbitrum, and zkSync. The protocol uses an upgradeable Transparent Proxy (EIP-1967) controlled by a multi-sig DAO consisting of 4 out of 7 members. The review's objective was to evaluate upgrade compatibility, ensuring that future contract upgrades won't break existing state, introduce new attack vectors, or compromise the protocol's economic guarantees.

The review identified seven critical findings, ranging from low to medium severity, that could impact the protocol's safety during upgrades:

1. Storage Slot Collision in InterestRateModelV2: A new variable added in the upgraded InterestRateModelV2 contract overwrites the existing multiplierPerYear slot, leading to incorrect interest calculations. If exploited, it could inflate borrowing capacity and drain reserves, potentially causing losses of up to $200 million.

2. Uninitialized Storage Gap in RewardsDistributor: The upgraded RewardsDistributor contract reduces the reserved slot count from 50 to 30, leaving the remaining slots uninitialized. Malicious upgrades could write unintended data into these slots, redirecting reward emissions to an attacker's address, leading to reward token misallocation worth approximately $15 million.

3. Missing OnlyGovernor Guard on EmergencyPause: The EmergencyPause function, designed to be callable only by the DAO governor, can be invoked by any address with the PROPOSER_ROLE due to a missing onlyGovernor modifier. This oversight could allow malicious relayers or compromised keys to pause deposits and withdrawals during an upgrade, creating a temporary denial-of-service situation and enabling state skew attacks.

4. Replay-Attack on Bridge Messages: The BridgeExecutor contract validates incoming messages based on the msg.sender but fails to verify the chainId embedded in the payload. An attacker could exploit this by replaying a historic L2-to-L1 message after an upgrade, causing double-minting of aTokens and inflating the token supply by approximately 0.5% of the total TVL, or $30 million.

5. Upgradeable Proxy Admin Set to Upgradeable Contract: The DAO can change the proxy admin to any address, potentially leading to a "self-destruct-upgrade" path if an attacker sets the admin to a contract that itself is upgradeable. This could result in the attacker replacing the admin with a malicious contract that calls proxy.selfdestruct() or proxy.upgradeTo(address(0)), effectively disabling the protocol's upgradeability and freezing it permanently.

6. Missing Invariant Test for Total Supply Consistency: The protocol's test suite does not verify that totalSupply equals the sum of userDeposits plus accruedInterest after any upgrade. This oversight could allow subtle rounding behavior changes to occur, leading to hidden accounting discrepancies and "dust" accumulation or loss of funds over time.

In conclusion, the protocol's upgradeability model is fundamentally sound, but the identified storage-layout mismatches and governance guard omissions pose a material risk that could be exploited during or right after a scheduled upgrade. With an overall risk score of 7 out of 10 (elevated), addressing these concerns should be a top priority to maintain the platform's security and integrity.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

MCP Servers Had a Rough 48 Hours: 4 Unauthenticated CVEs

Between Monday morning and Tuesday night this week, four Model Context Protocol servers published CVE records for the same basic failure: every tool they expose is reachable with no authentication.

  • Four unauthenticated CVEs discovered in MCP servers
  • Vulnerabilities allow unauthorized access and code execution
  • Fixes available but not widely adopted

Detecting Vulnerabilities in Go with gosec

En los laboratorios analizamos el código de una aplicación con SonarCloud, Snyk y Semgrep. En este ejercicio el punto de mira es el mismo código fuente, pero con una herramienta que no usamos en los…

  • gosec, a Go static analyzer, finds 17 vulnerabilities in deliberately flawed application
  • Five vulnerabilities are high severity, 11 are medium severity, one is low severity
  • gosec integration into automated pipelines crucial for comprehensive code analysis

Why I built a spaced-repetition app for coding drills

I used to read a solution, nod, and move on. A week later I could not write the same thing from scratch. Understanding something while it is on the screen and being able to produce it yourself are…

  • Author struggled with retaining coding concepts after reading about them
  • Developed Daily Coding, a spaced-repetition web app for coding drills
  • App uses JavaScript/TypeScript, SQL, and page building drills, free and ad-free

More from Sunday 4 October →