Skip to content

Immediate Restaking fee updates allow atomic post-epoch snapshot manipulation and theft of vault yield #281

Description

@sko94

there is a bug in the operator_set_fee.rs` here this part

operator.operator_fee_bps = new_fee_bps.into();

it's updates the operator fee immediately. there is no delay, no “effective next epoch” rule, and no ramp-up period. Because Tip Router later reads this live fee when creating the reward snapshot, an operator can briefly change the fee to 100%, let the snapshot capture that value, and then restore the original fee in the same transaction. The live Operator account ends up showing the old fee again, but the snapshot keeps 100% and uses it to split rewards from the already-completed epoch. T
the vulnerability is not that operators are allowed to change fees; it is that fee changes take effect instantly and can be applied retroactively to rewards that were already earned under the previous fee.
i have a e2e poc that show this with imapct if need it

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions