Fractional v2 contest - Kulk0's results

A collective ownership platform for NFTs on Ethereum.

General Information

Platform: Code4rena

Start Date: 07/07/2022

Pot Size: $75,000 USDC

Total HM: 32

Participants: 141

Period: 7 days

Judge: HardlyDifficult

Total Solo HM: 4

Id: 144

League: ETH

Fractional

Findings Distribution

Researcher Performance

Rank: 104/141

Findings: 1

Award: $61.94

🌟 Selected for report: 0

🚀 Solo Findings: 0

In Vault.install, the selectors have to correspond to the plugins. If they don't it could make the contracts unusable because the contract would call the wrong function on the incorrect address.

I'm not sure this is even an issue, though, since there will be probably a front end from which the users will create the vaults, but if there is somebody that will create it manually and he wouldn't input it correctly, he could lose the assets he would send to the Vault.

Recommendations:

There is no way to check if the selector and the address correspond to each other inside the contract, so maybe a comment inside the contract warning the users before creating the contract would be enough.

#0 - HardlyDifficult

2022-08-08T12:46:38Z

AuditHub

A portfolio for auditors, a security profile for protocols, a hub for web3 security.

Built bymalatrax © 2024

Auditors

Browse

Contests

Browse

Get in touch

ContactTwitter