Trail of Bits

Ondo

Type

Security review

Client

Ondo Finance

Date

2022-10

Domain

Blockchain

Effort

4 wks

Section

Ethereum/EVM

Trail of Bits's security review of Ondo Finance (Oct 2022) identified 8 issues: 2 high, 2 low, and 4 informational.

Findings · 8

  1. 1 Risk of DoS attacks due to rate limits High
  2. 2 Risk of accounting errors due to missing check in the invest function High
  3. 3 Missing functionality in the _rescueTokens function Low
  4. 4 Solidity compiler optimizations can be problematic Informational
  5. 5 Lack of contract existence check on call Informational
  6. 6 Arbitrage opportunity in the PSM contract Informational
  7. 7 Problematic use of safeApprove Low
  8. 8 Lack of upper bound for fees and system parameters Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related