Executive brief
Marginal v1, a decentralized finance protocol for leveraged trading, contains a flaw in its smart contract logic. An attacker can exploit this vulnerability to settle large debt positions for a fraction of their actual cost. This could lead to significant financial loss for the protocol's liquidity providers and damage the platform's reputation.
Technical details
The Marginal v1-core smart contracts contain an unsafe downcasting vulnerability (CWE-681). When converting between numeric types (e.g., from a larger integer type to a smaller one), the protocol fails to validate that the value fits within the destination type's range. This truncation allows an attacker to manipulate debt settlement calculations. Specifically, a large debt value can be downcast into a much smaller value, enabling the attacker to close out significant positions for a negligible cost. The vulnerability is located in the core settlement logic and can be triggered by any network participant interacting with the contract.
Affected products
- Marginal Protocol v1-core up to (including) 1.0.2
Timeline
- 2026-04-07: disclosed: Initial CVE publication
- 2026-05-22: advisory: NVD analysis and enrichment completed
References
- https://cvefeed.io/cwe/detail/cwe-681-incorrect-conversion-between-numeric-types
- https://github.com/MarginalProtocol
- https://marginal.gitbook.io/docs
- https://medium.com/@clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-critical-vulnerability-using-verifiably-false-0a27b92ac2db
- https://scs.owasp.org/SCWE/SCSVS-CODE/SCWE-041/