Audit Open Original ↗
NuCypher
Type
Security review
Client
NuCypher
Date
2019-02
Domain
Blockchain
Effort
4 wks
Section
Ethereum/EVM
Trail of Bits's security review of NuCypher (Feb 2019) identified 7 issues: 2 high, 2 medium, 2 low, and 1 informational.
Findings · 7
- 1 verifyState does not accurately check memory layout High
- 2 Contract upgrades can catastrophically fail if the storage layout changes Low
- 3 finishUpgrade lacks same checks as contract constructor Low
- 4 Contract owner can arbitrarily replay finishUpgrade Medium
- 5 Proxy has public methods that shadow implementation High
- 6 Lack of events for critical operations Informational
- 7 Dispatcher does not confirm contract’s existence prior to returning Medium
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related