Audit Open Original ↗
Yield Protocol
Type
Security review
Client
Yield
Date
2020-08
Domain
Blockchain
Effort
6 wks
Section
Ethereum/EVM
Trail of Bits's security review of Yield (Aug 2020) identified 11 issues: 1 high, 1 medium, 5 low, 2 informational, and 2 undetermined.
Findings · 11
- 1 Flash minting can be used to redeem fyDAI Medium
- 2 Permission-granting is too simplistic and not flexible enough Low
- 3 pot.chi() value is never updated Low
- 4 Lack of validation when setting the maturity value Low
- 5 Delegates can be added or removed repeatedly to bloat logs Informational
- 6 Withdrawing from the Controller allows accounts to contain dust Low
- 7 Solidity compiler optimizations can be dangerous Undetermined
- 8 Lack of chainID validation allows signatures to be re-used across forks High
- 9 Permit opens the door for griefing contracts that interact with the Yield Protocol Informational
- 10 Pool initialization is unprotected Low
- 11 Computation of DAI/fyDAI to buy/sell is imprecise Undetermined
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related