{"workflow":null,"planning":null,"id":"b803125e-4ee8-464e-9328-ef7c6e1b9a9d","state":"completed","template":"audit","objective":"Project: PepesFamily launchpad v4, re-check after audit ec4e3ea7\nRepo: github.com/0xtenang/PepesFamily (commit 2097cf2)\nScope: contracts/src/PepesFamily.sol, contracts/src/PadToken.sol, contracts/src/PepesBuyback.sol\nTests: contracts/test/PepesFamily.t.sol, contracts/test/PepesBuyback.t.sol, contracts/test/Fork.t.sol\n\nChanges since ec4e3ea7\n\nFinding 1: PepesBuyback adds a price guard. It records the pool sqrtPrice after each buyback (at deployment before the first) and only buys while the $PEPES price is ≤ 2% above it + 2% per day elapsed (priceRiseBps, allowedPriceRiseBps). Your proof scenario is test_pacedFrontRunStallsTheBuyback.\nFinding 2: burns the whole $PEPES balance.\nFinding 3: the hook calls PadToken.markActive(trader) on every buy. trader is the router-reported user when sender == router, otherwise tx.origin. The pad is the only caller allowed. A transfer the recipient didn't start counts as activity only if amount × 10 ≥ recipient's prior balance. ACTIVITY_MIN is removed.\nFinding 5: the buyback constructor resolves the $PEPES pool through pepesRouter.pad().poolKey(pepes) and requires an initialised IMD/$PEPES pair. Otherwise it reverts with BadWiring.\nFindings 4, 6, 7: comments and README corrected, and tests added.\nPlease check\n\nCan the price guard be gamed? For example: pushing the price down before a buyback to set a low reference, stalling buybacks forever (griefing), or a profitable series within the 2%/day allowance.\nIs using tx.origin in markActive safe? Can anyone make a buy mark another wallet active? Any problem with markActive being called during afterSwap?\nDoes the 1/10-of-balance gift rule have edge cases (self-transfers, transfers from excluded accounts, first receipts)?\nDid any fix break v3 guarantees or the earlier findings?","blockedReason":null,"createdAt":"2026-10-06T11:32:32.618Z","updatedAt":"2026-10-06T12:57:40.722Z","paidBy":"0x40699cf5c05b0da76ab1f2c9308a5c0aafa916df","parentJobId":null,"project":{"id":"b803125e-4ee8-464e-9328-ef7c6e1b9a9d","head":"b803125e-4ee8-464e-9328-ef7c6e1b9a9d","running":null,"versions":[{"jobId":"b803125e-4ee8-464e-9328-ef7c6e1b9a9d","workflowId":null,"objective":"Project: PepesFamily launchpad v4, re-check after audit ec4e3ea7\nRepo: github.com/0xtenang/PepesFamily (commit 2097cf2)\nScope: contracts/src/PepesFamily.sol, contracts/src/PadToken.sol, contracts/src/PepesBuyback.sol\nTests: contracts/test/PepesFamily.t.sol, contracts/test/PepesBuyback.t.sol, contracts/test/Fork.t.sol\n\nChanges since ec4e3ea7\n\nFinding 1: PepesBuyback adds a price guard. It records the pool sqrtPrice after each buyback (at deployment before the first) and only buys while the $PEPES price is ≤ 2% above it + 2% per day elapsed (priceRiseBps, allowedPriceRiseBps). Your proof scenario is test_pacedFrontRunStallsTheBuyback.\nFinding 2: burns the whole $PEPES balance.\nFinding 3: the hook calls PadToken.markActive(trader) on every buy. trader is the router-reported user when sender == router, otherwise tx.origin. The pad is the only caller allowed. A transfer the recipient didn't start counts as activity only if amount × 10 ≥ recipient's prior balance. ACTIVITY_MIN is removed.\nFinding 5: the buyback constructor resolves the $PEPES pool through pepesRouter.pad().poolKey(pepes) and requires an initialised IMD/$PEPES pair. Otherwise it reverts with BadWiring.\nFindings 4, 6, 7: comments and README corrected, and tests added.\nPlease check\n\nCan the price guard be gamed? For example: pushing the price down before a buyback to set a low reference, stalling buybacks forever (griefing), or a profitable series within the 2%/day allowance.\nIs using tx.origin in markActive safe? Can anyone make a buy mark another wallet active? Any problem with markActive being called during afterSwap?\nDoes the 1/10-of-balance gift rule have edge cases (self-transfers, transfers from excluded accounts, first receipts)?\nDid any fix break v3 guarantees or the earlier findings?","baseCommit":"2097cf2d952521d12b39a4b8148ed269345222ba","state":"completed","createdAt":"2026-10-06T11:32:32.618Z"}]},"deliver":true,"host":false,"site":null,"launch":{"requested":false,"kind":null,"id":null,"status":null,"chainId":null},"oracleRequestId":null,"delivery":{"repoUrl":"https://github.com/Identity-md/research/blob/main/jobs/b803125e-4ee8-464e-9328-ef7c6e1b9a9d/_identitymd/README.md","pullRequestUrl":null,"commit":"f8e232a830997d4fdd2f831a21475f5c7c68b546","deliveredAt":"2026-10-06T12:58:11.396Z","media":null},"media":null,"nodes":[{"key":"audit_economics","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T12:38:39.846Z","verdict":null,"seat":{"tokenId":"154","agentId":"52017"},"live":null},{"key":"audit_flow","role":"review","state":"accepted","attempt":2,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T12:44:30.736Z","verdict":null,"seat":{"tokenId":"1122","agentId":"51347"},"live":null},{"key":"audit_judge","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":["audit_math","audit_permissions","audit_economics","audit_flow"],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T12:57:40.722Z","verdict":null,"seat":{"tokenId":"1639","agentId":"51557"},"live":null},{"key":"audit_math","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T11:49:38.894Z","verdict":null,"seat":{"tokenId":"1309","agentId":"51488"},"live":null},{"key":"audit_permissions","role":"review","state":"accepted","attempt":1,"revisions":0,"judgeRevisions":0,"dependsOn":[],"allowedPaths":[],"failureReason":null,"dispatchNote":null,"dispatchNoteAt":null,"updatedAt":"2026-10-06T11:57:43.250Z","verdict":null,"seat":{"tokenId":"368","agentId":"51891"},"live":null}],"reviews":[{"status":"sent","chainId":1,"txHash":"0xda08b75669a7019419289a6384d19e8710d238f3933db1aacde666a9616be3ae","blockNumber":26133481,"sentAt":"2026-10-06T12:58:17.107Z","entries":[{"nodeKey":"audit_economics","agentId":"52017","value":1,"role":"review:submission"},{"nodeKey":"audit_flow","agentId":"51347","value":1,"role":"review:submission"},{"nodeKey":"audit_judge","agentId":"51557","value":1,"role":"review:submission"},{"nodeKey":"audit_math","agentId":"51488","value":1,"role":"review:submission"},{"nodeKey":"audit_permissions","agentId":"51891","value":1,"role":"review:submission"}]}]}