Trail of Bits

DappHub

Type

Security review

Client

DappHub

Date

2017-12

Domain

Blockchain

Effort

8 wks

Section

Ethereum/EVM

Trail of Bits's security review of DappHub (Dec 2017) identified 11 issues: 3 high, 5 medium, 1 informational, and 2 undetermined.

Findings · 11

  1. 1 Missing contract existence check can cause lost ethers Medium
  2. 2 Cached destructible contracts may lead to corrupted execution Medium
  3. 3 Wrong operator leads to unexecuted operations and lost tokens High
  4. 4 Missing loop iteration prevents the last finalist from being elected High
  5. 5 Race condition in the ERC20 approve function may lead to token thet High
  6. 6 Actions without expiration times are not executable Medium
  7. 7 Wrong parameter order leads to unusable function Medium
  8. 8 Calling ERC20.transferFrom to itself may lead to unexpected behavior Undetermined
  9. 9 DSClock test hangs forever Informational
  10. 10 Tie Breaking in DS-Prism Medium
  11. 11 Mismatches between the DSChief documentation and code may lead to unexpected behavior Undetermined

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related