Trail of Bits

Seaport Protocol

Type

Security review

Client

OpenSea

Date

2022-05

Domain

Blockchain

Effort

4 wks

Section

Ethereum/EVM

Trail of Bits's security review of OpenSea (May 2022) identified 11 issues: 2 low, 7 informational, and 2 undetermined.

Findings · 11

  1. 1 Project dependencies contain vulnerabilities Low
  2. 2 Lack of zero-value checks on functions Informational
  3. 3 Solidity compiler optimizations can be problematic Informational
  4. 4 Error-prone approach to data validation Undetermined
  5. 5 User-controlled return data can trigger an out-of-gas error Informational
  6. 6 Failure to check existence of orders before cancellation Informational
  7. 7 Callbacks can be used to alter token state Informational
  8. 8 Use of Yul optimization pipeline and solc 0.8.13 Informational
  9. 9 Potential front-running of channel-removal transactions Informational
  10. 10 Lack of a zero-value check in the validate function Low
  11. 11 fulfillAdvancedOrder may revert and prevent order fulfillment Undetermined

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related