Audit Open Original ↗
TokenCard
Type
Security review
Client
TokenCard
Date
2019-05
Domain
Blockchain
Effort
5 wks
Section
Ethereum/EVM
Trail of Bits's security review of TokenCard (May 2019) identified 13 issues: 4 medium, 8 low, and 1 undetermined.
Findings · 13
- 1 Wallet and Licence are incompatible with non-standard ERC20 tokens Low
- 2 Parsing large JSON integers could result in interoperability issues Low
- 3 Base64 decoding does not validate its input Low
- 4 Solidity compiler optimizations can be dangerous Undetermined
- 5 Lack of contract existence check may mislead the user about the transaction’s result Medium
- 6 Contracts used as dependencies do not track upstream changes Low
- 7 No sanitization is performed when the Oraclize query is constructed Medium
- 8 _licenceAmountScaled can be incorrectly initialized Low
- 9 Multiplication over low can block certain wallet operations Low
- 10 AddressWhitelist owner can be added to the whitelist Medium
- 11 Date validation is insu ficient and returns imprecise timestamps Low
- 12 Malicious price source can block withdrawal of funds Low
- 13 Daily limits may be bypassed via executeTransaction for certain tokens Medium
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related