The Negative Invoice — Python Bug Hunt
Inspired by the classic negative-amount exploits that have hit payment processors: transfer -$500 to someone and the money flows backwards, straight past…
- Language: Python
- Layer: Backend
- Difficulty: Easy
- Concepts: Validation, Payments
- Modelled on: PayPal-class exploits
- Visible tests: a normal transfer moves the money; negative amounts are rejected; insufficient funds are rejected
- Reward: 50 XP for a complete fix
Briefing
Inspired by the classic negative-amount exploits that have hit payment processors: transfer -$500 to someone and the money flows backwards, straight past every balance check.
transfer.py moves money between accounts. It trusts the amount.
Bug report
BUG-MINUS · Priority: Critical (fraud) · Reported by: fintech risk
transfer(balances, src, dst, amount) rules:
- amount must be a positive number -> otherwise raise ValueError
- src must hold at least amount -> otherwise raise ValueError
- on success, debit src and credit dst; return the updated dict
Observed: amount=-500 silently DRAINS the destination account.
Logs
[xfer] alice->bob amount=-500 | alice 1500 (+500), bob -300 (-500)The code as shipped
src/pay/transfer.py (editable)
# Moves money between account balances (a dict of name -> cents).
def transfer(balances, src, dst, amount):
balances[src] = balances[src] - amount
balances[dst] = balances[dst] + amount
return balances
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.