▐ homomorph ▌

rules / HM008

HM008 plaintext-branch-on-encrypted HIGH

Control flow branches on encrypted data instead of using FHE.select

Why it matters

Encrypted programs must be data-oblivious: the same instructions run whatever the plaintext is. Two anti-patterns break this. (1) Decrypting inside a condition (`if (FHE.decrypt(x))`) both leaks the value on-chain and, on current fhEVM, is not even possible synchronously. (2) Performing `FHE.sub(balance, amount)` with no `FHE.select` guard: because the comparison result is itself encrypted the contract cannot `require` it, so the subtraction silently wraps on underflow and an attacker can mint value or drain a balance while every observer sees a normal transaction.

Fix

Compute the condition encrypted and select: `ebool ok = FHE.le(amount, balances[from]); euint64 delta = FHE.select(ok, amount, FHE.asEuint64(0));` then update both sides with `delta`. Never branch in plaintext on a decrypted value.

Check locally

homomorph scan . --rules HM008