code-423n4 / 2022-04-phuture-findings

0 stars 0 forks source link

QA Report #86

Open code423n4 opened 2 years ago

code423n4 commented 2 years ago

Low

1. Unsafe ERC20 Operations

Proof of Concept

  phuture/IndexLogic.sol::139 => vToken.transfer(address(vToken), accountBalance);
  phuture/vToken.sol::210 => _NAV.transfer(_from, _to, _amount);

Recommendation

Use openzeppelin's safeTransfer() function.

Tools used

c4udit.