Trail of Bits

Paxos Standard

Type

Security review

Client

Paxos

Date

2018-10

Domain

Blockchain

Effort

4 wks

Section

Ethereum/EVM

Trail of Bits's security review of Paxos (Oct 2018) identified 6 issues: 2 low, and 4 informational.

Findings · 6

  1. 1 lawEnforcementRole can freeze the supplyController Informational
  2. 2 lawEnforcementRole can decrease supply Informational
  3. 3 lawEnforcementRole operations are highly visible Informational
  4. 4 supplyController address changes result in orphaned balances Low
  5. 5 Users can send PAX to supplyController Informational
  6. 6 Insuficient Logging Low

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related