Audit Open Original ↗
Origin Protocol
Type
Security review
Client
Origin Protocol
Date
2018-11
Domain
Blockchain
Effort
4 wks
Section
Ethereum/EVM
Trail of Bits's security review of Origin Protocol (Nov 2018) identified 11 issues: 4 high, 4 medium, 1 low, and 2 informational.
Findings · 11
- 1 Marketplace OGN balance is drainable through withdrawListing High
- 2 Disputes are front-runnable by a buyer Medium
- 3 Remote code execution through arbitrary ERC20 implementation High
- 4 ERC20 approve race conditions Informational
- 5 Marketplace contract can trap funds if the whitelist is disabled Medium
- 6 OriginToken contract migration breaks Marketplace o fer references High
- 7 Withdrawn listing prevents seller from withdrawing submitted o fers Low
- 8 Seller finalization of an o fer with an a filiate and commission results in trapped funds Medium
- 9 OriginToken migration while unpaused leads to inconsistent state Medium
- 10 Marketplace cannot be Paused Informational
- 11 Tokens with external code execution can lead to the t of tokens through reentrancy High
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related