Trail of Bits

Opyn

Type

Security review

Client

Opyn

Date

2021-11

Domain

Blockchain

Effort

6 wks

Section

Ethereum/EVM

Trail of Bits's security review of Opyn (Nov 2021) identified 8 issues: 4 high, 3 low, and 1 undetermined.

Findings · 8

  1. 1 onERC721Received callback is never called when new tokens are minted or transferred High
  2. 2 Users can create vaults that cannot be liquidated High
  3. 3 Solidity compiler optimizations can be problematic Undetermined
  4. 4 Initialization function can be front-run Low
  5. 5 The computation of the normalization factor can fail High
  6. 6 Users can disrupt the bookkeeping of the strategy when it is deployed High
  7. 7 Lack of access controls allows anyone to deposit Uniswap tokens Low
  8. 8 Front-running a withdrawal operation can cause it to revert Low

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related