Trail of Bits

FraxGov

Type

Security review

Client

Frax Finance

Date

2023-05

Domain

Blockchain

Effort

4 wks

Section

Frax Finance

Trail of Bits's security review of Frax Finance (May 2023) identified 8 issues: 2 high, 1 medium, 4 informational, and 1 undetermined.

Findings · 8

  1. 1 Race condition in FraxGovernorOmega target validation High
  2. 2 Vulnerable project dependency Undetermined
  3. 3 Replay protection missing in castVoteWithReasonAndParamsBySig Medium
  4. 4 Ability to lock any user’s tokens using deposit_for Informational
  5. 5 The relay function can be used to call critical safe functions High
  6. 6 Votes can be delegated to contracts Informational
  7. 7 Lack of public documentation regarding voting power expiry Informational
  8. 8 Spamming risk in propose functions Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related