T09 · Insecure Skill Coding Practices
- Location
safety/limits.py:7- Finding
Daily-loss and consecutive-loss safety controls are nonfunctional
- Content
View full analysis
= Config.MAX_TRADES_PER_DAY: return False if self.daily_loss >= Config.MAX_DAILY_LOSS_USD: return False balance = self.get_usdc_balance() if balance < Config.MIN_USDC_BALANCE: return False if time.time() - self.last_trade_time < 300: # 5 min cooldown return False return True ``` ```python self.daily_trades += 1 self.last_trade_time = time.time() ``` ### Technical Analysis `daily_loss` and `consecutive_losses` are initialized but are never updated from fills, closed positions, or realized account P&L. Therefore, the configured daily-loss limit and the advertised pause after three consecutive losses cannot trigger. The code also does not associate `daily_trades` with a calendar date or reset it at the start of a new UTC trading day. As a result, the five-trade control is a lifetime counter for the current process rather than a daily limit. Restarting the process resets all counters, allowing the nominal limits to be bypassed unintentionally or deliberately. The documentation describes these controls as hard safety limits that cannot be bypassed, but the implementation only checks volatile in-memory values that are not reconciled against exchange state. ### Attack Path 1. An operator launches the bot against a funded Hyperliquid mainnet wallet. 2. The bot submits one or more losing market orders. 3. The exchange realizes losses when positi ...[truncated 925 chars]- Remediation
View remediation
