Trail of Bits

ParaSpace

Type

Security review

Client

Paraspace

Date

2022-11

Domain

Crypto

Effort

7 wks

Section

Substrate

Trail of Bits's security review of Paraspace (Nov 2022) identified 15 issues: 2 high, 5 low, and 8 informational.

Findings · 15

  1. 1 Unconventional test structure Informational
  2. 2 Insucient event generation Low
  3. 3 Missing supportsInterface functions Low
  4. 4 ERC1155 asset type is defined but not implemented Informational
  5. 5 executeMintToTreasury silently skips non-ERC20 tokens Low
  6. 6 getReservesData does not set all AggregatedReserveData fields Low
  7. 7 Excessive type repetition in returned tuples Informational
  8. 8 Incorrect grace period could result in denial of service Low
  9. 9 Incorrect accounting in _transferCollaterizable Informational
  10. 10 IPriceOracle interface is used only in tests Informational
  11. 11 Manual ERC721 transfers could be claimed as NTokens by anyone High
  12. 12 Inconsistent behavior between NToken and PToken liquidations Informational
  13. 13 Missing asset type checks in ValidationLogic library Informational
  14. 14 Uniswap v3 NFT flash claims may lead to undercollateralization High
  15. 15 Non-injective hash encoding in getClaimKeyHash Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related