Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungThe Homelab Is the New Resume(21.09.2026 um 00:29 Uhr)
Sichere ProgrammierungPerl 🐪 Weekly #791 - The Dark Side is here!(21.09.2026 um 00:44 Uhr)
Sichere Programmierungbro.js v3.0.0 – What’s new(21.09.2026 um 00:44 Uhr)
Sichere ProgrammierungFour bugs my test suite couldn't catch(21.09.2026 um 00:49 Uhr)
Sichere ProgrammierungAutomating Deployment with Github Actions(21.09.2026 um 00:49 Uhr)
Linux Tipps & HardeningKernel prepatch 7.3-rc4(21.09.2026 um 00:52 Uhr)
IT NachrichtenHow to use Xbox mode on your Windows PC(21.09.2026 um 00:30 Uhr)
Sichere ProgrammierungThe Homelab Is the New Resume(21.09.2026 um 00:29 Uhr)
Sichere ProgrammierungPerl 🐪 Weekly #791 - The Dark Side is here!(21.09.2026 um 00:44 Uhr)
Sichere Programmierungbro.js v3.0.0 – What’s new(21.09.2026 um 00:44 Uhr)
Sichere ProgrammierungFour bugs my test suite couldn't catch(21.09.2026 um 00:49 Uhr)
Sichere ProgrammierungAutomating Deployment with Github Actions(21.09.2026 um 00:49 Uhr)
Linux Tipps & HardeningKernel prepatch 7.3-rc4(21.09.2026 um 00:52 Uhr)
IT NachrichtenHow to use Xbox mode on your Windows PC(21.09.2026 um 00:30 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Why Casting Double to Decimal Won't Save Your Financial Data 💸 (A Bug Hunt Story)

Reagiere als Erste:r — dein Feedback zählt!

Today at work, I was deep in the trenches of a large legacy codebase, tracking down a weird bug. The application handles a lot of financial data, and at a certain point in the logic, an account balance was supposed to be exactly 0.

Instead, the system was throwing errors because the value was something like 0.000000000000000014.

Ah, yes. The dreaded floating-point noise.

When I dug into the source code, I found the culprit. A previous developer had used a double to calculate the financial values, and then, right at the end, did something like this to "fix" it:

decimal finalBalance = (decimal)calculatedDoubleBalance;

Spoiler alert: This does not work.

Here is why casting a Double to a Decimal won't save you, and why you need to understand the difference between the two when dealing with money.

🥊 Double vs. Decimal: What’s the difference?

To understand the bug, we have to look at how computers store numbers under the hood.

The Double (Floating-Point)

A double (short for double-precision floating-point) represents numbers using Base-2 (binary) fractions.
Because it uses binary, it can't perfectly represent all Base-10 (decimal) fractions. Just like 1/3 results in 0.333333... in our normal math, fractions like 0.1 result in an endlessly repeating binary fraction for a computer.

To make it fit into memory, the computer cuts it off, resulting in a tiny loss of precision.

  • Pros: Blazing fast, uses less memory, and can store astronomically large or microscopic numbers. Perfect for physics, graphics, and scientific calculations.
  • Cons: 0.1 + 0.2 equals 0.30000000000000004.

The Decimal

A decimal represents numbers using Base-10 math. It was specifically created to handle money and financial calculations. It stores exact decimal fractions. If you tell it to store 0.1, it stores exactly 0.1.

  • Pros: 100% precision for decimal numbers. No floating-point noise.
  • Cons: Slower to compute and takes up more memory (usually 128-bit vs a double's 64-bit).

🔍 Why the cast failed

In the bug I found today, the developer knew that the final output needed to be a Decimal. But because the math leading up to that point was done using Doubles, the precision was already lost.

Casting a corrupted Double into a Decimal is like taking a blurry, low-resolution photo and saving it as a massive 4K PNG. It doesn't magically restore the lost details; it just gives you a very high-resolution, blurry photo.

When you cast a double with floating-point noise to a decimal, the decimal faithfully records that exact noise.

Let's see it in action (C# example):

double deposit = 0.1;
double anotherDeposit = 0.2;
double doubleBalance = deposit + anotherDeposit; 
// doubleBalance is now 0.30000000000000004

// Let's try to "fix" it by casting!
decimal decimalBalance = (decimal)doubleBalance;

Console.WriteLine(decimalBalance); 
// Output: 0.30000000000000004 ❌ We just preserved the error!

Because the math was already executed as a double, the damage was done. When subtracting values later down the line, instead of hitting exactly 0, the system was left with microscopic pennies, breaking the business logic.

🛠️ How to handle this properly

If you are working with money, currencies, or any system where exact Base-10 precision is required, follow these rules:

1. NEVER use Double or Float for money.
Not in your database, not in your API payloads, and not in your code.

2. Use Decimal from start to finish.
Declare your variables as decimal right away.

decimal deposit = 0.1m;
decimal anotherDeposit = 0.2m;
decimal decimalBalance = deposit + anotherDeposit; 

Console.WriteLine(decimalBalance); 
// Output: 0.3 ✅

3. What if you have to deal with a legacy Double?
If you are consuming a legacy API or database that gives you a double, and you need to convert it to a decimal to do financial math, you need to use rounding.

double legacyValue = 0.30000000000000004;

// Round it to the precision of your currency (e.g., 2 decimal places) 
// BEFORE or DURING the transition to Decimal.
decimal cleanDecimal = Math.Round((decimal)legacyValue, 2); 

Console.WriteLine(cleanDecimal); // Output: 0.30 ✅

Final Thoughts

Finding this bug today was a great reminder that types matter. Double is great for calculating the trajectory of a rocket, but it's terrible for calculating someone's paycheck.

Have you ever spent hours chasing down a floating-point bug in your codebase? Let me know in the comments! 👇

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Why Casting Double to Decimal Won't Save Your Financial Data 💸 (A Bug Hunt Story)

Thematisch verwandte Begriffe: Casting, Double, Decimal, Wont · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-94084 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a t…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick