Smart contract Marginal v1 performs unsafe downcast, allowing attackers to settle a large debt position for a negligible asset cost.
References 5
https://cvefeed.io/cwe/detail/cwe-681-incorrect-conversion-between-numeric-types
cret@cert.org
https://github.com/MarginalProtocol
cret@cert.org
https://marginal.gitbook.io/docs
cret@cert.org
https://medium.com/@clarkcorrin/cve-2026-4931-how-spearbits-cantina-denied-a-cr…
cret@cert.org
https://scs.owasp.org/SCWE/SCSVS-CODE/SCWE-041/
cret@cert.org