code-423n4 / 2022-12-tigris-findings

8 stars 4 forks source link

QA Report #639

Closed code423n4 closed 1 year ago

code423n4 commented 1 year ago

See the markdown file with the details of this report here.

GalloDaSballo commented 1 year ago

Price data signing is untyped


No verification that orderType isn't greater than 2


Closing referral fees go to the last ref rather than opening order ref


No incentive to use BondNFT.release() instead of claim()


Protocol might reach insolvency from traders profit


GainsGoblin commented 1 year ago

We will keep price data signing untyped.

c4-sponsor commented 1 year ago

GainsGoblin marked the issue as sponsor confirmed

GalloDaSballo commented 1 year ago

3L 2R

GalloDaSballo commented 1 year ago

1L from Dups

4L 2R

c4-judge commented 1 year ago

GalloDaSballo marked the issue as grade-c