Audit Open Original ↗
Folks Finance Protocol
Type
Security review
Client
Folks Finance
Date
2022-11
Domain
Blockchain
Effort
6 wks
Section
Algorand
Trail of Bits's security review of Folks Finance (Nov 2022) identified 10 issues: 3 high, 1 medium, 5 low, and 1 informational.
Findings · 10
- 1 Ability to drain a pool by reusing a flash_loan_end index High
- 2 Lack of a two-step process for admin role transfers High
- 3 Insu cient validation of application initialization arguments Low
- 4 Ability to reuse swap indexes Informational
- 5 oracle_adapter could be forced to use outdated LP token information in price calculations Medium
- 6 Incorrect rounding directions in the calculation of borrowed asset amounts Low
- 7 Risk of global state variable collision High
- 8 Lack of documentation on strategies in case of system parameter update Low
- 9 Incorrect decoding of method arguments results in the use of invalid values Low
- 10 Lack of minimum / maximum bounds on user operation parameters Low
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related