Audit Open Original ↗
Reserve Protocol Solana DTFs
Type
Security review
Client
Reserve Protocol
Date
2025-04
Domain
Blockchain
Effort
2 wks
Section
Reserve Protocol
Trail of Bits's security review of Reserve Protocol (Apr 2025) identified 12 issues: 3 high, 1 medium, 2 low, and 6 informational.
Findings · 12
- 1 Incomplete building and testing instructions Informational
- 2 No Solana-specific documentation Informational
- 3 Testing deficiencies Informational
- 4 Accounts structs store fields in differing orders, making them difficult to compare Informational
- 5 DTF owner key compromise allows manipulation of DAOFeeConfig Medium
- 6 Trade instructions do not require a dtf_pogram_signer account High
- 7 Comparison against wrong constant in accrue_rewards High
- 8 remove_from_registrar succeeds if passed program IDs are not in accepted_programs Informational
- 9 update_folio has error-prone interface that can lock out the owner Low
- 10 add_tokens_to_basket does not check whether any of the values in mints is Pubkey::default() Informational
- 11 Incorrect TTL check in approve_trade Low
- 12 Folio owner can rug pull DTF shareholders High
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related