Urgent.News

What's breaking now, across thousands of outlets.

Tech

Protocol Upgrade Compatibility Review: Bitfinex

Protocol Upgrade Compatibility Review: Bitfinex Target Protocol : Bitfinex (TVL: $20712.0M) Protocol Upgrade Compatibility Review – Bitfinex TVL: ≈ $20.7 B (Ethereum + L2) Prepared by: [Your Firm] – Senior DeFi Security Research & Auditing Team Date: 2026‑10‑09 1. Executive Summary Bitfinex operates a multi‑chain ecosystem that includes the LEO token , a suite of margin‑trading contracts ,…

Bitfinex, a multi-chain trading platform with a $20.7 billion TVL across Ethereum and L2 networks, is preparing a significant protocol upgrade. This review by [Your Firm]'s senior DeFi security team identifies four critical issues that could lead to loss or freeze of hundreds of millions of dollars if left unaddressed.

The first issue involves storage-slot collisions in proxy-based contracts such as MarginEngineProxy, VaultManagerProxy, and BridgeAdapterProxy. New fields (maxLeverage, liquidationPenalty, l2BatchSize) are added before the existing protocolVersion, shifting its storage slot and causing the old implementation to read/write the wrong slots. This could lead to corrupted risk parameters, under-collateralised liquidations, and permanent vault freezes.

Secondly, the upgrade introduces unrestricted delegatecall to unverified libraries through a LibraryRegistry, which could allow malicious contracts to re-enter the core contract and modify balances or exfiltrate funds. The third issue is an L1/L2 state-root mismatch during batch settlement, where an attacker controlling the L2 sequencer could submit a root that omits liquidation events, allowing under-collateralised positions to survive.

The fourth and most critical issue is a governance timelock bypass via executeAfterDelay re‑entrancy in DAOExecutor and TimelockController. This could allow governance actions (like an upgrade to a malicious implementation) to be executed instantly, nullifying the intended delay.

Additional medium-severity vectors include oracle price-feed replay on L2, insufficient access-control on emergency pause, and re‑entrancy in batch-withdrawal flow. The review concludes that while the upgrade design is sound, these issues pose a "High" risk score of 7/10. The team recommends prioritizing storage layout fixes, library contract whitelisting, addition of inclusion proofs for batch settlement roots, and addressing the timelock bypass and oracle replay vulnerabilities.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Build & Release #3: I Deleted Every npm Token I Own

On October 7th I tried to publish @7onic-ui/tokens@0.3.7 and npm told me my own package didn't exist. npm error 404 Not Found - PUT https://registry.npmjs.org/@7onic-ui%2ftokens npm error 404…

  • Reporter deleted all npm tokens and NPMTOKEN secret from GitHub
  • Switched to Trusted Publishing for secure package publishing
  • Successfully published packages without authentication issues

More from Friday 9 October →