Infinite Leverage — Python Bug Hunt
Inspired by the 2019 "infinite money" exploit where a brokerage's margin math counted borrowed money as collateral for borrowing more.
- Language: Python
- Layer: Backend
- Difficulty: Hard
- Concepts: Finance, Validation
- Modelled on: Robinhood · 2019
- Visible tests: settled cash gets 2x leverage; pending deposits add nothing; borrowed funds reduce buying power
- Reward: 50 XP for a complete fix
Briefing
Inspired by the 2019 "infinite money" exploit where a brokerage's margin math counted borrowed money as collateral for borrowing more. Users looped it into six-figure positions on a $2,000 deposit.
margin.py computes buying power. Three inputs, one rule each — all three are wrong.
Bug report
BUG-∞-LEV · Priority: Existential · Reported by: clearing
buying_power(account) with 2x leverage:
- settled_cash counts at 2x
- pending deposits count at ZERO (not settled!)
- borrowed funds SUBTRACT from buying power, never add
account = {"settled_cash": c, "pending": p, "borrowed": b}
Observed: pending and borrowed both counted at 2x — deposit, borrow, repeat.
Logs
[margin] settled=2000 pending=50000 borrowed=48000 -> power=200000 (!!)The code as shipped
src/broker/margin.py (editable)
# Computes buying power for a margin account.
LEVERAGE = 2
def buying_power(account):
total = account["settled_cash"] + account["pending"] + account["borrowed"]
return total * LEVERAGE
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.