waveygist

Infinifi Shorttimelock - 23/09/2026 13:06 - HIGH

Summary

Opens chain 143 USDC routing by authorizing a CCTP/Chainlink connector, enabling USDC, mapping it to an outpost asset, and configuring previously unset CCTP domain 15. Sets OutlandVault for PortalHub and OutlandFarm, registers the farm as type 2, and assigns the vault a previously unset FixedPriceOracle. No tokens move in these calls, but the new valuation and cross-chain routing configuration could affect funds handled later.

Analysis

Configuration changes

  1. Accounting oracle: Accounting (0x7A5C5dbA4fbD0e1e1A2eCDBe752fAe55f6E842B3) assigns FixedPriceOracle (0x168DF792845BA1bd80d485399de63a4110b03242) to OutlandVault (0x77776F422B7EB0A95ccD35fBd088A5957D4408eA). The vault’s oracle entry was unset before this call. This establishes a valuation source for the vault in Accounting; the oracle’s price and pricing methodology are not supplied, so the resulting valuation cannot be checked here.
  2. Vault references: PortalHub (0x13025F34C1ec2A16bF68f3a3c4e986a3E85CED61) and OutlandFarm (0xA7c1DAEAA5D97e1319B4Ff6Cdf658F5C4582A27E) each set their vault reference to OutlandVault. The farm’s reference changes from unset to OutlandVault. PortalHub’s prior vault setting was not provided, so its before→after delta is unknown. The farm source advises reducing old-vault shares to zero when changing vaults; its previously unset reference does not establish an old vault whose shares need migrating.
  3. Farm registration: FarmRegistry (0xF5f2718708f471e43968271956CC01aaA8c46119) registers OutlandFarm under type 2. The supplied context does not define what type 2 permits, and it does not give the registry’s previous entry. The farm’s live assetToken() getter identifies USDC as its asset token.
  4. Connector authorization: PortalHub authorizes ConnectorCCTP_Chainlink (0x3373784A7a52A07F9339aA8F60403420cC602c52) as a connector. This adds a routing authorization; no assets are transferred by the call. The connector’s live usdc() getter identifies USDC, but its operational behavior is not established by that getter alone.
  5. Chain-143 asset enablement: The connector enables chain 143 for the configured chain asset, mainnet USDC (0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48). This is permission to use that asset in the connector’s chain configuration, not a USDC movement.
  6. Cross-chain mapping: PortalHub configures a bidirectional mapping for chain 143 between mainnet USDC and the designated outpost asset (0x754704Bc059F8C67012fEd69BC8A327a5aafb603). The mapping specifies which addresses PortalHub should associate across chains; the supplied evidence does not independently verify the outpost asset’s identity or the correctness of that association.
  7. CCTP domain: The connector sets chain 143 to CCTP domain 15. Before the call, the stored domain was 0 and its configured flag was false; afterward, the domain is 15 and configured. The flag matters because domain 0 can be a valid configured value rather than necessarily meaning “unset.”

Asset flows and execution evidence

These calls change references, registrations, authorizations, and routing parameters; they do not themselves move tokens. They can nevertheless determine how later USDC transfers and vault accounting are handled. Independent simulations report success and the expected events for calls 1, 2, and 4–8. No simulation result is shown for call 3, and individual successes do not prove that the full batch executes atomically.

Risk assessment

HIGH risk. The batch combines a newly assigned vault valuation oracle with farm registration and a newly authorized cross-chain USDC route. An incorrect fixed price could affect subsequent accounting, while an incorrect asset mapping, CCTP domain, or connector configuration could affect subsequent cross-chain handling of funds. The absence of an immediate token transfer limits the direct impact of these calls, but does not remove the exposure created for later activity. Before relying on the route, verify the oracle’s configured price and methodology, the chain-143 outpost asset, and the chain-to-domain association; those checks cannot be completed from the supplied data.

Call Flow

From: 0x4B174afbeD7b98BA01F50E36109EEE5e6d327c32

  1. setOracle(address,address) on 0x7A5C5dbA4fbD0e1e1A2eCDBe752fAe55f6E842B3 (Accounting)

  2. setVault(address) on 0x13025F34C1ec2A16bF68f3a3c4e986a3E85CED61 (PortalHub)

  3. setVault(address) on 0xA7c1DAEAA5D97e1319B4Ff6Cdf658F5C4582A27E (OutlandFarm)

    • address _vault: 0x77776F422B7EB0A95ccD35fBd088A5957D4408eA (OutlandVault (OV-143, 18 dec))
    • Simulation diagnostic: reverted — not a predicted governance failure (independent simulation; omitted from the risk prompt)
  4. addFarms(uint256,address[]) on 0xF5f2718708f471e43968271956CC01aaA8c46119 (FarmRegistry)

  5. addConnector(address) on 0x13025F34C1ec2A16bF68f3a3c4e986a3E85CED61 (PortalHub)

  6. enableChainAsset(uint256,address) on 0x3373784A7a52A07F9339aA8F60403420cC602c52 (ConnectorCCTP_Chainlink)

  7. setAssetMapping(uint256,address,address) on 0x13025F34C1ec2A16bF68f3a3c4e986a3E85CED61 (PortalHub)

  8. setCctpDomain(uint256,uint32) on 0x3373784A7a52A07F9339aA8F60403420cC602c52 (ConnectorCCTP_Chainlink)

    • uint256 _chainId: 143
    • uint32 _domain: 15
    • Independent simulation: SUCCESS (does not prove the batch succeeds atomically)

Current State

Reference

Address Label Role Description
0x4B174afbeD7b98BA01F50E36109EEE5e6d327c32 Infinifi Shorttimelock Executor Executor: Execution authority for the governance transaction
0x7A5C5dbA4fbD0e1e1A2eCDBe752fAe55f6E842B3 Accounting Call target Call target: Receives setOracle(address,address)
0x77776F422B7EB0A95ccD35fBd088A5957D4408eA OutlandVault (OV-143, 18 dec) Calldata argument Calldata argument: Passed as _asset to setOracle(address,address)
Calldata argument: Passed as _vault to setVault(address)
0x168DF792845BA1bd80d485399de63a4110b03242 FixedPriceOracle Calldata argument Calldata argument: Passed as _oracle to setOracle(address,address)
0x13025F34C1ec2A16bF68f3a3c4e986a3E85CED61 PortalHub Call target Call target: Receives setVault(address)
Call target: Receives addConnector(address)
Call target: Receives setAssetMapping(uint256,address,address)
0xA7c1DAEAA5D97e1319B4Ff6Cdf658F5C4582A27E OutlandFarm Call target; Calldata argument Call target: Receives setVault(address)
Calldata argument: Passed as _list to addFarms(uint256,address[])
0xF5f2718708f471e43968271956CC01aaA8c46119 FarmRegistry Call target Call target: Receives addFarms(uint256,address[])
0x3373784A7a52A07F9339aA8F60403420cC602c52 ConnectorCCTP_Chainlink Calldata argument; Call target Calldata argument: Passed as _connector to addConnector(address)
Call target: Receives enableChainAsset(uint256,address)
Call target: Receives setCctpDomain(uint256,uint32)
0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48 Circle: USDC Token (USDC, 6 dec) Calldata argument Calldata argument: Passed as _chainAsset to enableChainAsset(uint256,address)
Calldata argument: Passed as _hubAsset to setAssetMapping(uint256,address,address)
0x754704Bc059F8C67012fEd69BC8A327a5aafb603 — Calldata argument Calldata argument: Passed as _outpostAsset to setAssetMapping(uint256,address,address)