Trail of Bits

Ampleforth

Type

Security review

Client

Ampleforth

Date

2018-11

Domain

Blockchain

Effort

4 wks

Section

Ethereum/EVM

Trail of Bits's security review of Ampleforth (Nov 2018) identified 7 issues: 4 low, 2 informational, and 1 undetermined.

Findings · 7

  1. 1 Rebasing will fail if no market sources are fresh Low
  2. 2 Malicious or erroneous MarketSource can break rebasing Low
  3. 3 Zos-lib is deprecated Informational
  4. 4 Possible reentrancy if the minimum rebase interval is zero Low
  5. 5 Market source removal is dangerous Informational
  6. 6 Contract upgrades can catastrophically fail if the storage layout changes Low
  7. 7 Rebase predictability may make Ampleforth a target for arbitrage Undetermined

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related