Yesterday, we posted the full write-up of a finding that stemmed from a heap-invariant violation caused by incomplete reheapification after removing an arbitrary element from a Cartesian Merkle Tree.
If you found it difficult to visualize how reheapification preserves the heap