Agent skill

Economic Attack Vectors

by ccashwell in ccashwell/evm-cortex

Economic attack vectors and defenses for DeFi protocols. An agent skill from ccashwell/evm-cortex.

MITAuto-check passedBusiness, Finance & HR

Install Economic Attack Vectors

skills CLI
$ npx skills add ccashwell/evm-cortex --skill economic-attack-vectors -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ccashwell/evm-cortex economic-attack-vectors --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ccashwell/evm-cortex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/economic-attack-vectors .claude/skills/economic-attack-vectors && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
economic-attack-vectors
GitHub stars
131
Token cost
~1.7k tokens
SKILL.md length
206 words
Files
1
Skills in repo
89
Repo updated
First seen
Licence
MIT

At a glance

Economic attack vectors and defenses for DeFi protocols. An agent skill from ccashwell/evm-cortex.

  • Designing vaults
  • SKILL.md covers First Depositor Inflation…, Donation Attack, Share Price Manipulation and Sandwich Attacks on Liquidity…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Any system with share-based accounting

What it does

Economic Attack Vectors is an agent skill from ccashwell/evm-cortex. Economic attack vectors and defenses for DeFi protocols. Use when designing vaults, lending pools, AMMs, or any system with share-based accounting. Covers first depositor inflation, donation attacks, sandwich attacks on liquidity, JIT liquidity, and flash loan leveraged attacks.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Accounting and bookkeeping, Banking and insurance and Crypto and DeFi analysis. The repository describes itself as: Ethereum protocol engineering squad for AI coding assistants. The licence is MIT.

When your agent uses it

  • Designing vaults
  • Any system with share-based accounting

Example prompts

  • “/economic-attack-vectors”

What it can do on your machine

Read from SKILL.md and the folder at commit f8f3301. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are solidity).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Economic Attack Vectors loads about 1.7k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 206 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ccashwell/evm-cortex at commit f8f3301, republished under its MIT licence (© ccashwell). 206 words, ~1,712 tokens.

Download SKILL.mdSave it as .claude/skills/economic-attack-vectors/SKILL.md (or your agent's skills folder).
name
economic-attack-vectors
description
Economic attack vectors and defenses for DeFi protocols. Use when designing vaults, lending pools, AMMs, or any system with share-based accounting. Covers first depositor inflation, donation attacks, sandwich attacks on liquidity, JIT liquidity, and flash loan leveraged attacks.

Economic Attack Vectors

First Depositor Inflation Attack (ERC-4626)

The most common vault attack. The first depositor can manipulate the share price to steal from subsequent depositors.

Attack Steps
1. Attacker deposits 1 wei → receives 1 share
2. Attacker donates 1e18 tokens directly to vault (not via deposit)
3. Vault state: 1 share, (1 + 1e18) assets
4. Victim deposits 1.5e18 tokens
5. Shares minted = 1.5e18 * 1 / (1 + 1e18) = 0 shares (rounds to 0)
6. Attacker redeems 1 share → gets all 2.5e18 tokens
7. Victim loses ~1.5e18 tokens
Defense: Virtual Shares and Assets
solidity
contract SafeVault is ERC4626 {
    uint256 private constant VIRTUAL_SHARES = 1e3;   // 1000 virtual shares
    uint256 private constant VIRTUAL_ASSETS = 1;     // 1 virtual asset

    function totalAssets() public view override returns (uint256) {
        return IERC20(asset()).balanceOf(address(this)) + VIRTUAL_ASSETS;
    }

    function _decimalsOffset() internal pure override returns (uint8) {
        return 3; // adds 1e3 virtual shares
    }
}
Defense: Minimum Initial Deposit
solidity
uint256 public constant MIN_INITIAL_DEPOSIT = 1e6; // 1 USDC or equivalent

function deposit(uint256 assets, address receiver) public override returns (uint256 shares) {
    if (totalSupply() == 0 && assets < MIN_INITIAL_DEPOSIT) {
        revert InitialDepositTooSmall();
    }
    return super.deposit(assets, receiver);
}
Defense: Dead Shares

Lock a small amount of shares on first deposit to establish a non-manipulable base.

solidity
function _afterDeposit(uint256 assets, uint256 shares) internal override {
    if (totalSupply() == shares) {
        // First deposit — burn some shares to dead address
        uint256 deadShares = 1e3;
        _mint(address(0xdead), deadShares);
    }
}

Donation Attack

An attacker sends tokens directly to a contract (via transfer, not deposit) to manipulate internal accounting.

solidity
// VULNERABLE: relies on balanceOf for accounting
function getExchangeRate() public view returns (uint256) {
    return IERC20(asset).balanceOf(address(this)) / totalShares;
    // Attacker can inflate by donating tokens
}

// SAFE: track deposits explicitly
uint256 public totalManagedAssets;

function deposit(uint256 amount) external {
    totalManagedAssets += amount;
    IERC20(asset).safeTransferFrom(msg.sender, address(this), amount);
}

function getExchangeRate() public view returns (uint256) {
    return totalManagedAssets / totalShares; // not manipulable via donation
}

Share Price Manipulation

Manipulating the share price (assets per share) to extract value.

solidity
// Attack on lending protocol:
// 1. Deposit collateral, borrow assets
// 2. Donate to vault → inflate share price
// 3. Collateral (measured in shares) appears more valuable
// 4. Borrow more than collateral is worth
// 5. Default on the loan

// Defense: use internal accounting, not balanceOf
// Defense: price oracle for share valuation (not instantaneous price)

Sandwich Attacks on Liquidity Provision

1. Attacker sees victim's addLiquidity TX in mempool
2. Front-run: large swap moves the price
3. Victim adds liquidity at skewed ratio
4. Back-run: attacker swaps back, profiting from the imbalance
Defense
solidity
function addLiquidity(
    uint256 amount0Desired,
    uint256 amount1Desired,
    uint256 amount0Min,     // minimum token0 actually deposited
    uint256 amount1Min,     // minimum token1 actually deposited
    uint256 deadline
) external returns (uint256 liquidity) {
    if (block.timestamp > deadline) revert Expired();

    (uint256 amount0, uint256 amount1) = _calculateOptimalAmounts(
        amount0Desired, amount1Desired
    );

    if (amount0 < amount0Min) revert InsufficientAmount0();
    if (amount1 < amount1Min) revert InsufficientAmount1();

    // ...
}

Just-in-Time (JIT) Liquidity

MEV searchers add concentrated liquidity just before a large swap and remove it immediately after, capturing swap fees without taking long-term IL risk.

solidity
// Defense: time-weighted fee distribution
mapping(uint256 => uint256) public positionMintBlock;

function collectFees(uint256 positionId) external {
    uint256 mintBlock = positionMintBlock[positionId];
    uint256 blocksActive = block.number - mintBlock;

    if (blocksActive < MIN_ACTIVE_BLOCKS) {
        revert PositionTooNew(blocksActive, MIN_ACTIVE_BLOCKS);
    }
    // Fees are proportional to time * liquidity, not just liquidity
}

Flash Loan Leveraged Attacks

Flash loans amplify any profitable attack by providing unlimited capital.

solidity
// Generic pattern:
// 1. Flash borrow X tokens
// 2. Use X to manipulate state (price, governance, collateral)
// 3. Extract profit from manipulated state
// 4. Return X + fee

// Defense principle: any state that can be profitably manipulated
// with temporary capital must be resistant to single-block manipulation

// Specific defenses:
// - Time-weighted readings (TWAP, voting snapshots)
// - Multi-block delays (deposit → borrow separation)
// - Rate limiting (max action per block)

Governance Token Economic Attacks

solidity
// Attack: borrow governance tokens → propose + vote → drain treasury
// Defense: snapshot voting + proposal threshold + voting delay

// Attack: buy tokens → vote → dump tokens
// Defense: time-locked voting power (must hold tokens for N blocks)

function getVotingPower(address account) public view returns (uint256) {
    uint256 balance = token.balanceOf(account);
    uint256 holdDuration = block.number - firstPurchaseBlock[account];

    if (holdDuration < MIN_HOLD_BLOCKS) return 0;

    // Optional: voting power scales with hold time
    uint256 multiplier = Math.min(holdDuration / BLOCKS_PER_MONTH, MAX_MULTIPLIER);
    return balance * multiplier / MAX_MULTIPLIER;
}

Economic Attack Defense Checklist

  • ERC-4626 vaults use virtual shares/assets or dead shares
  • No reliance on balanceOf for internal accounting
  • Minimum deposit amounts to prevent dust attacks
  • Liquidity provision has slippage protection (minAmount0, minAmount1)
  • Deadline parameters on all value-sensitive operations
  • Share price not manipulable via direct token transfers
  • Governance uses snapshot voting with minimum hold periods
  • Flash loan amplifiable state changes have multi-block delays
  • Rate limiting on critical operations (max per block/epoch)

© ccashwell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/economic-attack-vectors of ccashwell/evm-cortex.

Open the folder on GitHubat commit f8f3301

Compare with similar skills

Economic Attack Vectors next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Economic Attack Vectors compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Economic Attack Vectors this skillccashwell/evm-cortex131—~1.7kAutomated safety check: PassMIT
Swapper Depositswapperfinance/swapper-toolkit852—~1.8kAutomated safety check: PassMIT
Okx Cex Earnokx/agent-skills1862 repos~3.3kAutomated safety check: PassMIT
Oracle Flashloan Analysisquillai-network/quillshield_skills130—~2.8kAutomated safety check: PassMIT
Squadsinternet-court/internet-court-skill6.5k2 repos~5.9kAutomated safety check: PassApache-2.0
Starknet Defiinternet-court/internet-court-skill6.5k1 repos~2.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Swapper Deposit

    swapperfinance/swapper-toolkit

    Deposit and bridge funds into a wallet or protocol using Swapper Finance.

    852 GitHub stars~1.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • Okx Cex Earn

    okx/agent-skills

    Manages OKX Simple Earn (flexible savings/lending), Flash Earn, On-chain Earn (staking/DeFi), Dual Investment (DCD/双币赢), and AutoEarn (自动赚币) via the okx CLI.

    186 GitHub starsUsed in 2 repos~3.3k tokens
    Business, Finance & HRAuto-check passed
  • Oracle Flashloan Analysis

    quillai-network/quillshield_skills

    Detects price oracle manipulation and flash loan attack vectors in DeFi smart contracts.

    130 GitHub stars~2.8k tokensUpdated 6 mo ago
    Business, Finance & HRAuto-check passed
  • Squads

    internet-court/internet-court-skill

    Complete guide for Squads Protocol - Solana's leading smart account and multisig infrastructure.

    6.5k GitHub starsUsed in 2 repos~5.9k tokens
    Business, Finance & HRAuto-check passed
  • Starknet Defi

    internet-court/internet-court-skill

    Execute DeFi operations on Starknet including token swaps via avnu aggregator, DCA recurring buys, STRK staking, and lending/borrowing.

    6.5k GitHub starsUsed in 1 repo~2.3k tokens
    Business, Finance & HRAuto-check: notes
  • Defi Connector

    Signal-Execution-Labs/forex-trading-ai-agent

    Connect to DeFi protocols for staking, lending, yield farming, and liquidity provision.

    162 GitHub stars~2.4k tokensUpdated 25 days ago
    Business, Finance & HRAuto-check passed

More from ccashwell/evm-cortex

All 89 skills in this repo
  • Xray Pre Audit

    ccashwell/evm-cortex

    A skill your agent uses when preparing for a security audit, performing reconnaissance on a new codebase, or creating a protocol overview.

    131 GitHub stars~25k tokensUpdated 10 days ago
    Auto-check passed
  • Aave Integration

    ccashwell/evm-cortex

    A skill your agent uses when integrating with Aave V3 for lending, borrowing, flash loans, or building on top of Aave markets.

    131 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Access Control Patterns

    ccashwell/evm-cortex

    Access control design patterns for Solidity protocols. An agent skill from ccashwell/evm-cortex.

    131 GitHub stars~1.8k tokensUpdated 10 days ago
    Auto-check passed
  • Anvil Patterns

    ccashwell/evm-cortex

    A skill your agent uses when running a local Ethereum node with Anvil.

    131 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Audit Breadth Scan

    ccashwell/evm-cortex

    A skill your agent uses when performing systematic breadth-first review of all contracts during a security audit.

    131 GitHub stars~1.4k tokensUpdated 10 days ago
    Auto-check passed
  • Audit Depth Analysis

    ccashwell/evm-cortex

    A skill your agent uses when performing deep analysis of specific findings or high-risk areas during a security audit.

    131 GitHub stars~1.6k tokensUpdated 10 days ago
    Auto-check passed

Questions about Economic Attack Vectors

What does Economic Attack Vectors do?

Economic attack vectors and defenses for DeFi protocols. An agent skill from ccashwell/evm-cortex. Economic Attack Vectors is an agent skill from ccashwell/evm-cortex. Economic attack vectors and defenses for DeFi protocols.

When should I use Economic Attack Vectors?

Economic Attack Vectors fits situations like: designing vaults; any system with share-based accounting.

How do I install Economic Attack Vectors in Claude Code?

Run `npx skills add ccashwell/evm-cortex --skill economic-attack-vectors -a claude-code`. Or copy the skill folder (skills/economic-attack-vectors in ccashwell/evm-cortex) into .claude/skills/economic-attack-vectors in your project. Claude Code loads it when a task matches its description.

How do I install Economic Attack Vectors in Codex?

Run `npx skills add ccashwell/evm-cortex --skill economic-attack-vectors -a codex`. Or copy the skill folder (skills/economic-attack-vectors in ccashwell/evm-cortex) into .agents/skills/economic-attack-vectors in your project. Codex loads it when a task matches its description.

Can I use Economic Attack Vectors in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ccashwell/evm-cortex --skill economic-attack-vectors -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/economic-attack-vectors, .gemini/skills/economic-attack-vectors, .github/skills/economic-attack-vectors and .opencode/skills/economic-attack-vectors in your project.

What does Economic Attack Vectors need to run?

SKILL.md names no scripts, command-line tools or credentials: Economic Attack Vectors is instructions for the agent only.

Does Economic Attack Vectors access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Economic Attack Vectors safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Economic Attack Vectors use?

Economic Attack Vectors is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Economic Attack Vectors use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Economic Attack Vectors?

Skills that share tags, products or a category with Economic Attack Vectors: Swapper Deposit (swapperfinance/swapper-toolkit, 852 stars), Okx Cex Earn (okx/agent-skills, 186 stars), Oracle Flashloan Analysis (quillai-network/quillshield_skills, 130 stars) and Squads (internet-court/internet-court-skill, 6.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Economic Attack Vectors?

ccashwell (a GitHub user) maintains it in ccashwell/evm-cortex, which has 131 GitHub stars. The repository holds 89 skills in this directory. The repository was last updated on September 30, 2026.

Source: ccashwell/evm-cortex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.