Shared authority budget race

Parallel children consume more than a single aggregate limit because each reads the same old balance.

01 / Attack path

How the boundary is crossed

Two billing agents both see $10,000 remaining and each submits an $8,000 refund.

Attack path and interception point
  1. 01Lower-trust input
  2. 02Attempted instruction
  3. 03Protected action
  4. 04Enforced decision

02 / Containment

Where bounded authority limits the effect

Atomically reserve against one budget before effect, settle or release reservations after known outcomes and reconcile unknown ones.

03 / Failure and evidence

The attacker’s opportunity and the defender’s record

Exploit condition

Independent child-local counters turn one $10,000 permission into $16,000 of refunds.

Evidence to retain

Record reservation IDs, competing attempts, executor outcomes and authoritative remaining balance.

04 / Canonical scope

Why this reference stands alone

Shared authority budgets explains the accounting model; this threat isolates the concurrency exploit.

Protocol or attack trace

Parallel reservation race

Sequence

Two refund children read $10,000 available, then each tries to spend $8,000.

Negative test

Atomic reservation permits only one; second sees $2,000 and is denied.

Primary references

Read the underlying material

Architecture discussion

Choose one consequential action and make its boundary explicit.

Request a Conversation