Guardian's review of Token for Aria, published September 2025. The report records 2 findings, including 1 low and 1 informational.
- Published
- Review window
- September 23, 2025
- Language
- Solidity
- Chains
- Story, BNB Chain
- Sector
- Real-world assets
- 0 Critical
- 0 High
- 0 Medium
- 1 Low
- 1 Informational
Scope
1 file in scope · 10 nSLOC
| File | nSLOC | Lines |
|---|---|---|
contracts/aria/token/Aria.sol | 10 | 16 |
Findings 2
-
L-01 Low Invalid ClaimAdmin__ZeroAddress Revert Best Practices Acknowledged
Description
When
token_ != token, the functionsreleasableandvestedAmountrevert withClaimAdmin__ZeroAddress(), which does not represent the true reason for the error.Recommendation
Change the revert name to match the cause of the error.
-
I-01 Informational
increaseAllowance/decreaseAllowanceDiscontinued Warning AcknowledgedDescription
The OpenZeppelin team removed
increaseAllowanceanddecreaseAllowancestarting in v5.x (discussion in OZ #4583, removal confirmed Jan 2024). These functions were never part of the ERC-20 standard — they were provided by OZ as convenience helpers to mitigate approval race conditions.Recommendation
- Audit dependencies: Check if the protocol or its integrators call
increaseAllowanceordecreaseAllowance. - Fallback to
approve: Replace with directapprove(spender, newAmount)calls, ensuring correct allowance handling. - Custom restore (optional): If your protocol needs these helpers for UX, re-implement them explicitly in your token contract — but document clearly that they’re non-standard.
- Audit dependencies: Check if the protocol or its integrators call
No findings match.
More from Aria
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
