Closed MillianoConti closed 5 years ago
Auditing time 1 day
@MrCrambo assigned
Auditing time: 1 day
@RideSolo assigned
Auditing time: 1 day.
@danbogd assigned
Audit paused.
My report is finished.
My report is finished
Nexo smart contract security audit report performed by Callisto Security Audit Department
Сommit hash 3571169b3365adfc92c5bd743cc75b5184a2172a.
In total, 3 issues were reported including:
1 low severity issues.
1 notes.
1 owner privileges (the ability of an owner to manipulate contract, may be risky for investors).
No critical security issues were found.
It is possible to double withdrawal attack. More details here.
Owner allows himself to call transferFrom
function from investors, community and advisers address, so there is risk to investors, that owner will transfer this tokens to another address.
https://github.com/nexofinance/NEXO-Token/blob/master/contracts/NexoToken.sol#L103
Don't forget to change addresses before deploy contract.
The audited smart contract can be deployed. Only low severity issues were found during the audit.
https://gist.github.com/yuriy77k/2bf5ef25e14b3c8fe974092f082e73ef
https://gist.github.com/yuriy77k/35cb280c011e56ae697b72d5dd0c379e
https://gist.github.com/yuriy77k/c8775b71c10309e21c343bd1400f965c
Audit request
Nexo is the most advanced and trusted instant crypto lending provider on a global scale, servicing 40+ currencies across more than 200 jurisdictions. https://nexo.io/
Source code
https://github.com/nexofinance/NEXO-Token/blob/master/contracts/NexoToken.sol
Disclosure policy
info@nexo.io
Platform
Eth
Number of lines:
164