Audit Open Original ↗
ParaSpace
Type
Security review
Client
Paraspace
Date
2022-11
Domain
Blockchain
Effort
7 wks
Section
Substrate
Trail of Bits's security review of Paraspace (Nov 2022) identified 15 issues: 2 high, 5 low, and 8 informational.
Findings · 15
- 1 Unconventional test structure Informational
- 2 Insu cient event generation Low
- 3 Missing supportsInterface functions Low
- 4 ERC1155 asset type is defined but not implemented Informational
- 5 executeMintToTreasury silently skips non-ERC20 tokens Low
- 6 getReservesData does not set all AggregatedReserveData fields Low
- 7 Excessive type repetition in returned tuples Informational
- 8 Incorrect grace period could result in denial of service Low
- 9 Incorrect accounting in _transferCollaterizable Informational
- 10 IPriceOracle interface is used only in tests Informational
- 11 Manual ERC721 transfers could be claimed as NTokens by anyone High
- 12 Inconsistent behavior between NToken and PToken liquidations Informational
- 13 Missing asset type checks in ValidationLogic library Informational
- 14 Uniswap v3 NFT flash claims may lead to undercollateralization High
- 15 Non-injective hash encoding in getClaimKeyHash Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related