T09 · Insecure Skill Coding Practices
- Location
scripts/grid-bot.js:73- Finding
Order ownership is inferred only from instrument and size, allowing unrelated orders to be cancelled
- Content
View full analysis
Math.abs(parseFloat(o.sz) - CONFIG.sizePerGrid) < 0.000001) .map(o => ({ instId: CONFIG.instId, ordId: o.ordId })); if (toCancel.length > 0) { // Batch cancel await Promise.all(toCancel.map(o => client.request('/trade/cancel-order', 'POST', JSON.stringify(o)))); } ``` ### Technical Analysis During rescaling, the bot identifies its orders solely by comparing each pending order's size with `CONFIG.sizePerGrid`. The instrument has already been selected by the API query, but neither the exchange order ID nor a bot-specific client order identifier is validated against persistent ownership records. Order size is not a unique ownership attribute. Manual orders and orders created by other strategies can legitimately use the same instrument and quantity. Those orders will satisfy the filter and be submitted to the OKX cancellation endpoint. ### Attack Path 1. A manual trader or another automated strategy creates a pending order for the configured instrument. 2. The order quantity equals `CONFIG.sizePerGrid` within the hardcoded tolerance. 3. The market price enters the bot's rescaling trigger zone. 4. The maintenance script retrieves all pending orders for that instrument. 5. The unrelated order passes the size-based filter. 6. The bot sends its `ordId` to `/trade/cancel-order`. 7. OKX cancels the unrelated order using the configured account's trade privileges. ### Impact Assessment The flaw permits cancellation of legitimate orders in the same OKX account and instrument. It can disrupt manual trading, hedging, risk controls, or independent automated strategies. The scope is limited to orders accessible through the configured API credentials, but the resulting loss of protective or strategic orders can creat ...[truncated 32 chars]- Remediation
View remediation
-` prefix. - Persist the exchange order IDs and client order IDs returned after successful placement. - Cancel an order only when its identifier is present in the bot's ownership registry or its validated client ID uses the expected prefix. - Keep ownership namespaces distinct for every bot configuration and instrument. - Do not use order size, price, or instrument as proof of ownership. - Reconcile persisted identifiers against OKX before rescaling and record every cancellation result in the audit log. ]]>
