Audit Open Original ↗
API3
Type
Security review
Client
API3
Date
2022-02
Domain
Blockchain
Effort
8 wks
Section
Ethereum/EVM
Trail of Bits's security review of API3 (Feb 2022) identified 9 issues: 2 high, 2 medium, 2 low, 2 informational, and 1 undetermined.
Findings · 9
- 1 Publish-subscribe protocol users are vulnerable to a denial of service High
- 2 Solidity compiler optimizations can be problematic Informational
- 3 Decisions to opt out of a monetization scheme are irreversible Medium
- 4 Depositors can front-run request-blocking transactions Medium
- 5 Incompatibility with non-standard ERC20 tokens Low
- 6 Compromise of a single oracle enables limited control of the dAPI value High
- 7 Project dependencies contain vulnerabilities Undetermined
- 8 DapiServer beacon data is accessible to all users Low
- 9 Misleading function name Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related