Description
In crates/precompiles/src/native_coin_authority.rs, the burn handler updates
total_supply using saturating_sub after calling balance_decr:
¤t_total_supply.saturating_sub(args.amount).to_be_bytes_vec()
The inline comment says "Underflow cannot happen due to the balance check", but
saturating_sub silently clamps to zero instead of reverting if the invariant
(total_supply >= individual balance) is ever violated due to a bug or storage
corruption. This would permanently corrupt global supply accounting with no
observable signal.
Expected behaviour
Any underflow should cause a hard revert, consistent with how mint already
guards against overflow with checked_add.
Suggested fix
Replace saturating_sub with checked_sub and revert with ERR_OVERFLOW on
underflow. A fix with two regression tests is ready.
Description
In
crates/precompiles/src/native_coin_authority.rs, theburnhandler updatestotal_supplyusingsaturating_subafter callingbalance_decr: