Audit Open Original ↗
Franklin Templeton
Type
Security review
Client
Franklin Templeton
Date
2023-05
Domain
Blockchain
Effort
4 wks
Section
Ethereum/EVM
Trail of Bits's security review of Franklin Templeton (May 2023) identified 15 issues: 4 high, 3 medium, 3 low, 4 informational, and 1 undetermined.
Findings · 15
- 1 Canceling all transaction requests causes DoS on MMF system High
- 2 Lack of validation in the IntentValidationModule contract can lead to inconsistent state High
- 3 Pending transactions cannot be settled Medium
- 4 Deauthorized accounts can keep shares of the MMF Medium
- 5 Solidity compiler optimizations can be problematic Informational
- 6 Project dependencies contain vulnerabilities Undetermined
- 7 Unimplemented getVersion function returns default value of zero Informational
- 8 The MultiSigGenVerifier threshold can be passed with a single signature High
- 9 Shareholders can renounce their authorization role Low
- 10 Risk of multiple dividend payouts in a day Medium
- 11 Shareholders can stop admin from deauthorizing them High
- 12 Total number of submitters in MultiSigGenVerifier contract can be more than allowed limit of MAX_SUBMITTERS Informational
- 13 Lack of contract existence check on target address Low
- 14 Pending transactions can trigger a DoS Informational
- 15 Dividend distribution has an incorrect rounding direction for negative rates Low
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related