Trail of Bits

Parabol Smart Contracts

Type

Security review

Client

Parabol Labs

Date

2024-05

Domain

Blockchain

Effort

2 wks

Section

Ethereum/EVM

Trail of Bits's security review of Parabol Labs (May 2024) identified 13 issues: 1 high, 5 low, and 7 informational.

Findings · 13

  1. 1 Incorrect ERC-7201 storage location in Denylister Low
  2. 2 ERC20BaseStorage._version is not initialized Informational
  3. 3 Incorrect comparison when setting the minimum lending limit Low
  4. 4 Income is erroneously calculated using accumulated income High
  5. 5 ERC20BaseUpgradeable and ERC721PermitUpgradeable should not signal support of IERC1271 Low
  6. 6 Updating the previous floating income can break an invariant Low
  7. 7 Incorrect parameter and event description Low
  8. 8 Inconsistent use of day parameter in event emission Informational
  9. 9 Protocol reports zero floating income for unset values Informational
  10. 10 Floating income is denominated in unclear units Informational
  11. 11 Unusual denominator values Informational
  12. 12 ERC20BaseUpgradeable initializer does not initialize ERC20Upgradeable Informational
  13. 13 Unnecessarily restrictive data type for timestamps Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related