Trail of Bits

Treehouse tETH Protocol

Type

Security review

Client

Treehouse

Date

2024-09

Domain

Blockchain

Effort

4 wks

Section

Ethereum/EVM

Trail of Bits's security review of Treehouse (Sep 2024) identified 6 issues: 2 medium, and 4 informational.

Findings · 6

  1. 1 Anyone can steal wstETH tokens accidentally transferred to the TreehouseRouter contract Medium
  2. 2 Underlying tokens can be “rescued” Medium
  3. 3 WstEth.wrap expects stETH amount instead of ETH amount Informational
  4. 4 Single-asset vault is not a single-asset vault Informational
  5. 5 Dangerous storage variable in Strategy contract due to use of delegatecall Informational
  6. 6 Missing return value check can lead to incorrect event emission Informational

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related