Infinite Leverage — Python Bug Hunt

Inspired by the 2019 "infinite money" exploit where a brokerage's margin math counted borrowed money as collateral for borrowing more.

  • Language: Python
  • Layer: Backend
  • Difficulty: Hard
  • Concepts: Finance, Validation
  • Modelled on: Robinhood · 2019
  • Visible tests: settled cash gets 2x leverage; pending deposits add nothing; borrowed funds reduce buying power
  • Reward: 50 XP for a complete fix

Briefing

Inspired by the 2019 "infinite money" exploit where a brokerage's margin math counted borrowed money as collateral for borrowing more. Users looped it into six-figure positions on a $2,000 deposit.

margin.py computes buying power. Three inputs, one rule each — all three are wrong.

Bug report

BUG-∞-LEV · Priority: Existential · Reported by: clearing

buying_power(account) with 2x leverage:

  • settled_cash counts at 2x
  • pending deposits count at ZERO (not settled!)
  • borrowed funds SUBTRACT from buying power, never add

account = {"settled_cash": c, "pending": p, "borrowed": b}

Observed: pending and borrowed both counted at 2x — deposit, borrow, repeat.

Logs

[margin] settled=2000 pending=50000 borrowed=48000 -> power=200000 (!!)

The code as shipped

src/broker/margin.py (editable)

# Computes buying power for a margin account.

LEVERAGE = 2

def buying_power(account):
    total = account["settled_cash"] + account["pending"] + account["borrowed"]
    return total * LEVERAGE

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.