Audit Open Original ↗
Token-2022 Program
Type
Security review
Client
Solana
Date
2023-02
Domain
Blockchain
Effort
1 wk
Section
Solana
Trail of Bits's security review of Solana (Feb 2023) identified 12 issues: 2 low, 7 informational, and 3 undetermined.
Findings · 12
- 1 Ok returned for malformed extension data Informational
- 2 Missing account ownership checks Undetermined
- 3 Use of a vulnerable dependency Undetermined
- 4 Large extension sizes can cause panics Informational
- 5 Unexpected function behavior Informational
- 6 Out of bounds access in the get_extension instruction Low
- 7 Iteration over empty data Informational
- 8 Missing check in UpdateMint instruction could result in inoperable mints Low
- 9 Incorrect test data description Informational
- 10 The Transfer and TransferWithFee instructions are identical Informational
- 11 Some instructions operate only on the lo bits of balances Undetermined
- 12 Instruction susceptible to front-running Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related