Audit Open Original ↗
Seaport Protocol
Type
Security review
Client
OpenSea
Date
2022-05
Domain
Blockchain
Effort
4 wks
Section
Ethereum/EVM
Trail of Bits's security review of OpenSea (May 2022) identified 11 issues: 2 low, 7 informational, and 2 undetermined.
Findings · 11
- 1 Project dependencies contain vulnerabilities Low
- 2 Lack of zero-value checks on functions Informational
- 3 Solidity compiler optimizations can be problematic Informational
- 4 Error-prone approach to data validation Undetermined
- 5 User-controlled return data can trigger an out-of-gas error Informational
- 6 Failure to check existence of orders before cancellation Informational
- 7 Callbacks can be used to alter token state Informational
- 8 Use of Yul optimization pipeline and solc 0.8.13 Informational
- 9 Potential front-running of channel-removal transactions Informational
- 10 Lack of a zero-value check in the validate function Low
- 11 fulfillAdvancedOrder may revert and prevent order fulfillment Undetermined
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related