Update to Recent Vulnerability Report

Update to the Recent Vulnerability Report

On Sunday, July 31st, the Integral team was alerted to a potential vulnerability within the protocol. The vulnerability was brought to our attention via a submission through Immunefi. Product and user safety are of utmost importance, and we treat each bug bounty submission seriously until proven otherwise. After a verification of the report and its contents, we paused trading and deposits for both FIVE and SIZE. There have been no reports of fund loss or LPs being exposed to excessive amounts of impermanent loss. Both FIVE and SIZE remain in withdraw-only function to ensure all users funds remain safe while the team works to resolve this issue.

In this article, we describe the reported vulnerability conceptually and with illustrative examples.


The bounty submission outlined a potential pathway of on-chain actions that if taken by a malicious trader and successfully completed, would give financial advantage to the trader (disadvantaging the LPs). In a worst case scenario this could be systematically repeated for profit across a sustained time period.

In summary: a malicious trader, Alice, could take advantage by setting her order submission to purposefully cancel, unless the TWAP settlement price is in her favor in which case she takes a later additional action to go through with the favorable settlement.

The key highlights are as follows:

  1. Alice could first create a large pending swap, with the intention for it to never go through by default (reversion/cancellation) unless a certain market price condition is met.
  2. Alice has a later action (for an on-chain loophole) that can be triggered closer to trade execution time. This can be activated at her discretion, which allows her pending trade to go through (acceptance of the upcoming trade settlement).
  3. Alice has a substantive advantage in ascertaining the settlement price (ie Oracle TWAP) as in the most extreme case, she could wait up to the block before settlement, before triggering her acceptance action. This is at a price that she knows to be favorable to her with high certainty as she could observe nearly the whole TWAP price period.

Fundamentally, Integral architecture is designed for committed traders to swap with LPs; in the long run no user type should have a systematic advantage, as some settlement scenarios favor LPs, and others favor the committed traders. The reported vulnerability showed how Alice could use a loophole pathway to avoid commitment by default, and selectively reach settlement only when the scenario favors her – hence forcing LPs to serve a continued series of worse-than-market swaps (@ prices uncompetitive to the LPs).

Until the dev team can come up with a solution for this loophole, currently SIZE and FIVE are in withdraw-only mode, as trading and deposits have been paused. We have also paused farming rewards until this issue is fixed. We appreciate the patience of the community through all of this.


Integral Insights


April 1st, 2024

Integral Insights March ‘24

We achieved several important milestones, including a new all-time-high daily volume for Arbitrum and the addition of four new pools on the Ethereum mainnet.


March 4th, 2024

Integral Insights February ‘24

Another milestone was reached on February 21st when Integral processed over $2 billion in cumulative volume.


February 1st, 2024

Integral Insights: January ‘24

Our initial launch with the ETH-RPL pool was a success, quickly elevating us to the second most utilized liquidity pool for this pair’s trading.


January 17th, 2024

Is Liquidity Fragmentation Really That Bad?

When the token evolves into a store of value, it attracts outside traders, focusing on trading costs and slippage. This is when concentrated liquidity truly shines.


January 2nd, 2024

2023 Review

At Integral, our focus remains on developing a sustainable product for on-chain trading, serving both traders and liquidity providers.


December 12th, 2023

Integral Now Rewards Liquidity Providers with Trading Fees on Ethereum Mainnet

This enhancement enables liquidity providers (LPs) to directly receive a portion or all trading fees from Integral pools.


December 6th, 2023

Integral Insights: November ‘23

During November, Integral processed an average of approximately 6 million in volume with around 1.5 million in TVL. The system’s overall capital utilization sits at around 350%. It is the 10th most used DEX on Ethereum.


November 28th, 2023

Integral Now Rewards Liquidity Providers with Trading Fees

This enhancement enables liquidity providers (LPs) to directly receive a portion or all trading fees from Integral pools.


November 15th, 2023

How Do University Blockchain Societies Gain So Many Votes?

Explore how university blockchain societies like FranklinDAO and Michigan Blockchain have grown into influential players in DAO governance, utilizing delegated votes and strategic partnerships to shape the future of DeFi protocols like Uniswap, Compound, and Aave.


November 6th, 2023

Integral Insight: October ‘23

We give an update for our work in October and highlight a profitable LP position from a long-term user.


October 26th, 2023

Understanding the Stakes in Lido’s Growing Share of Staked ETH

The community is arguing whether a protocol may have too much control over the Ethereum network. Lido controls a large percentage of staked ETH, which could have consequences for the network’s future security and neutrality.


October 14th, 2023

Changes to Staking and Farming

Looking back at our progress so far and to the future with new updates to staking and farming.


October 11th, 2023

Integral Insight: September ‘23

We give an update for our work in September with utilization going up on higher volume for our new pools.


October 11th, 2023

The Hottest Narratives of the Summer

What were the hottest narratives of the summer? Our DeFi research team delves into the growth of trading bots, RFV traders and more in this overview.


October 2nd, 2023

Uniswap Governance: A Deep Dive

Governance is considered a critical component for the decentralization and community-driven development of DeFi protocols. We take a look at one of the largest goverance ecostystems in DeFi, Uniswap. In this blog post, we'll discuss the landscape of Uniswap's governance, pulling data from empirical research to dissect the system's delegates and proposals, revealing some interesting findings.


September 19th, 2023

What is the DAI Savings Rate (DSR)?

Our research team takes a look at the DAI Savings Rate and its influence on various yield dynamics in DeFi.


September 15th, 2023

Integral Insight: August ‘23

We give an update for our work in August with cheaper gas fees and the launch of the Integral Relayer on Arbitrum!


September 7th, 2023

Integral Relayer Launches on Arbitrum

We are excited to announce the launch of the Atomic Relayer on Arbitrum. This will bring the efficient and tested system for atomic trades to the Arbitrum Layer 2 network!


August 26th, 2023

How CRV Got Sold OTC

In this post we cover how the Curve founder sold large amounts of CRV in over-the-counter trades in order to prevent a potentially catastrophic liquidation event in DeFi.


August 18th, 2023

Integral Insight: July '23

Sharing our progress in July: preparations for atomic swaps on Arbitrum, trading SIZE with lower gas fees and more.