The Negative Invoice — Python Bug Hunt

Inspired by the classic negative-amount exploits that have hit payment processors: transfer -$500 to someone and the money flows backwards, straight past…

  • Language: Python
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Validation, Payments
  • Modelled on: PayPal-class exploits
  • Visible tests: a normal transfer moves the money; negative amounts are rejected; insufficient funds are rejected
  • Reward: 50 XP for a complete fix

Briefing

Inspired by the classic negative-amount exploits that have hit payment processors: transfer -$500 to someone and the money flows backwards, straight past every balance check.

transfer.py moves money between accounts. It trusts the amount.

Bug report

BUG-MINUS · Priority: Critical (fraud) · Reported by: fintech risk

transfer(balances, src, dst, amount) rules:

  • amount must be a positive number -> otherwise raise ValueError
  • src must hold at least amount -> otherwise raise ValueError
  • on success, debit src and credit dst; return the updated dict

Observed: amount=-500 silently DRAINS the destination account.

Logs

[xfer] alice->bob amount=-500 | alice 1500 (+500), bob -300 (-500)

The code as shipped

src/pay/transfer.py (editable)

# Moves money between account balances (a dict of name -> cents).

def transfer(balances, src, dst, amount):
    balances[src] = balances[src] - amount
    balances[dst] = balances[dst] + amount
    return balances

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.