-
Notifications
You must be signed in to change notification settings - Fork 16
Open
Labels
👓 security-auditSecurity audit notes and findingsSecurity audit notes and findings
Description
- Limit the access to non-standard ERC20. Use the token integration checklist to evaluate collateral that should be allowed. For example, the system will not work as expected with tokens that take a fee on transfer
- Use Echidna to evaluate the impact of rounding. Several operations have a loss of precision due to the arithmetic rounding. As a result a user might receive less than expected, and this area should be investigated further
- Consider adding limits on how much assets can be withdrawn by AssetPool.claim. If the owner of the
AssetPoolis compromised, he can drain everything. A time-based limit of withdrawal might reduce the risks (note that the coverage pool was out of scope of my review)
pdyragapdyraga
Metadata
Metadata
Assignees
Labels
👓 security-auditSecurity audit notes and findingsSecurity audit notes and findings