Audit Open Original ↗
Reserve Protocol
Type
Security review
Client
Reserve Protocol
Date
2022-08
Domain
Blockchain
Effort
8 wks
Section
Reserve Protocol
Trail of Bits's security review of Reserve Protocol (Aug 2022) identified 15 issues: 5 high, 2 medium, 3 low, and 5 informational.
Findings · 15
- 1 Solidity compiler optimizations can be problematic Informational
- 2 Lack of a two-step process for contract ownership changes High
- 3 Unbounded and invalidly bounded system parameters may cause undefined behavior Medium
- 4 All auction initiation attempts may fail High
- 5 Per-block issuance limit can be bypassed Informational
- 6 All attempts to initiate auctions of defaulted collateral tokens will fail High
- 7 Fallen-target auctions can be prevented from occurring Informational
- 8 Faulty RToken issuance-cancellation process Low
- 9 Token auctions may not cover entire collateral token deficits Low
- 10 Inability to validate the recency of Aave and Compound oracle data Informational
- 11 An RSR seizure could leave the StRSR contract unusable High
- 12 System owner has excessive privileges High
- 13 Lack of zero address checks in Deployer constructor Low
- 14 RTokens can be purchased at a discount Medium
- 15 Inconsistent use of the FixLib library Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related