Trail of Bits

Dfinity

Type

Security review

Client

DFINITY

Date

2022-09

Domain

Crypto

Effort

4 wks

Section

Cryptography Reviews

Trail of Bits's security review of DFINITY (Sep 2022) identified 7 issues: 1 medium, 2 low, and 4 informational.

Findings · 7

  1. 1 Use of a custom transfer fee causes the creation of SNS neurons to fail Medium
  2. 2 Failure to ensure that all neurons have been created before the transition to Normal mode Informational
  3. 3 Unnecessary calls to unwrap in get_root_status Informational
  4. 4 Erroneous controller check in SnsRootCanister::set_dapp_controllers Low
  5. 5 Accounts with low balances are trimmed from the ICRC-1 ledger Informational
  6. 6 Potentially harmful remove_self_as_controller pattern Informational
  7. 7 Use of panicking functions poses a risk to the ledger’s archiving mechanism Low

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related