rules / HM008
HM008 plaintext-branch-on-encrypted HIGH
Control flow branches on encrypted data instead of using FHE.select
Why it matters
Encrypted programs must be data-oblivious: the same instructions run whatever the plaintext is. Two anti-patterns break this. (1) Decrypting inside a condition (`if (FHE.decrypt(x))`) both leaks the value on-chain and, on current fhEVM, is not even possible synchronously. (2) Performing `FHE.sub(balance, amount)` with no `FHE.select` guard: because the comparison result is itself encrypted the contract cannot `require` it, so the subtraction silently wraps on underflow and an attacker can mint value or drain a balance while every observer sees a normal transaction.
Fix
Compute the condition encrypted and select: `ebool ok = FHE.le(amount, balances[from]); euint64 delta = FHE.select(ok, amount, FHE.asEuint64(0));` then update both sides with `delta`. Never branch in plaintext on a decrypted value.
Check locally
homomorph scan . --rules HM008