Trail of Bits

Aura

Type

Security review

Client

Lindy Labs

Date

2023-08

Domain

Blockchain

Effort

8 wks

Section

Starknet

Trail of Bits's security review of Lindy Labs (Aug 2023) identified 13 issues: 2 high, 2 medium, 4 low, and 5 informational.

Findings · 13

  1. 1 Healthy loans can be liquidated High
  2. 2 block.timestamp is entirely determined by the sequencer Informational
  3. 3 Incorrect event emission in the Equalizer Low
  4. 4 Unchecked ERC-20 return values in the Absorber Low
  5. 5 Incorrect loop starting index in propagate_reward_errors Informational
  6. 6 Redistributions may not account for accrued interest on debt Medium
  7. 7 Marginal penalty may be scaled even if the threshold is equal to the absorption threshold Low
  8. 8 The share conversion rate may be zero even if the Absorber is not empty Medium
  9. 9 Missing safety check in the Purger’s absorb function Informational
  10. 10 Pair IDs are not validated to be unique Informational
  11. 11 Invalid price updates still update last_price_update_timestamp Low
  12. 12 Redistributions can occur even if the Shrine is killed High
  13. 13 Flash fee is not taken from receiver Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related