Audit Open Original ↗
Beanstalk
Type
Security review
Client
Beanstalk
Date
2022-07
Domain
Blockchain
Effort
8 wks
Section
Ethereum/EVM
Trail of Bits's security review of Beanstalk (Jul 2022) identified 13 issues: 3 high, 3 medium, 1 low, 3 informational, and 3 undetermined.
Findings · 13
- 1 Attackers could mint more Fertilizer than intended due to an unused variable Medium
- 2 Lack of a two-step process for ownership transfer High
- 3 Possible underflow could allow more Fertilizer than MAX_RAISE to be minted Medium
- 4 Risk of Fertilizer id collision that could result in loss of funds High
- 5 The sunrise() function rewards callers only with the base incentive Medium
- 6 Solidity compiler optimizations can be problematic Informational
- 7 Lack of support for external transfers of nonstandard ERC20 tokens Informational
- 8 Plot transfers from users with allowances revert if the owner has an existing pod listing Low
- 9 Users can sow more Bean tokens than are burned High
- 10 Pods may never ripen Undetermined
- 11 Bean and the o er backing it are strongly correlated Undetermined
- 12 Ability to whitelist assets uncorrelated with Bean price, misaligning governance incentives Undetermined
- 13 Unchecked burnFrom return value Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related