Closed c4-bot-10 closed 8 months ago
L2: It's been commented to: Ignore failure (it's EntryPoint's job to verify, not the account's). L3: It's proxy deployed which is different than your described finding.
1 L.
raymondfam marked the issue as insufficient quality report
raymondfam marked the issue as grade-c
Hi Please check L-01 Since it is related to revert txn when low level call returns false. I know it is 1 L but since L-01 is significant and it's fixing should be considered. so it's grade can be re-considered changing from current c. Thanks.
Hi @thenua3bhai L-01 is invalid, because the code following the check is a proper fallback FCL.ecdsa_verify()
for chains that don't support the VERIFIER
precompile.
If the sponsor were to follow this suggestion, that would constitute a High/Medium severity issue. That's a harmful recommendation, so grade-c
seems just fine.
See the markdown file with the details of this report here.