Trail of Bits

Increment Protocol

Type

Security review

Client

Increment Finance

Date

2022-09

Domain

Blockchain

Effort

4 wks

Section

Ethereum/EVM

Trail of Bits's security review of Increment Finance (Sep 2022) identified 13 issues: 3 high, 3 medium, 2 low, and 5 informational.

Findings · 13

  1. 1 Governance role is a single point of failure High
  2. 2 Inconsistent lower bounds on collateral weights Medium
  3. 3 Solidity compiler optimizations can be problematic Informational
  4. 4 Support for multiple reserve tokens allows for arbitrage Informational
  5. 5 Ownership transfers can be front-run High
  6. 6 Funding payments are made in the wrong token High
  7. 7 Excessive dust collection may lead to premature closures of long positions Medium
  8. 8 Problematic use of primitive operations on fixed-point integers Informational
  9. 9 Liquidations are vulnerable to sandwich attacks Medium
  10. 10 Accuracy of market and oracle TWAPs is tied to the frequency of user interactions Informational
  11. 11 Liquidations of short positions may fail because of insucient dust collection Low
  12. 12 Project dependencies contain vulnerabilities Low
  13. 13 Risks associated with oracle outages Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related