Audit Open Original ↗
Taraxa Ficus Bridge
Type
Security review
Client
Taraxa
Date
2024-07
Domain
Blockchain
Effort
1.6 wks
Section
Ethereum/EVM
Trail of Bits's security review of Taraxa (Jul 2024) identified 7 issues: 3 high, and 4 informational.
Findings · 7
- 1 Lack of safeTransfer usage for ERC20 High
- 2 The add function can revert Informational
- 3 G1 and G2 from method lack field point validation Informational
- 4 Missing validation allows signatures to be duplicated to finalize any PillarBlock High
- 5 Incorrect mapping key used in validation inside registerContract Informational
- 6 Reentrancy in applyState can lead to breaking the contract and stealing hook-enabled tokens High
- 7 Confusing application of settlementFee to locking native assets Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related