Guardian's review of Fee Update for Magna, published September 2024. The report records 3 findings, including 3 low.
- Published
- Review window
- September 16, 2024
- Language
- Solidity
- Chains
- Ethereum, Base, Optimism, Polygon, Arbitrum, BNB Chain
- Sector
- Infrastructure
- 0 Critical
- 0 High
- 0 Medium
- 3 Low
- 0 Informational
Findings 3
-
L-01 Low Excess ETH Not Refunded Validation Acknowledged
Description
In the
MerkleVestercontract the_handleClaimFeefunction does not refund any native value sent if the claim fee is assigned to 0.Because of this ETH may become trapped in the
MerkleVestercontract without being able to be rescued as there is no native recovery method.Recommendation
Consider reverting if the claim fee is 0 and the
msg.valueis nonzero. -
L-02 Low Fee Setter May Prevent Claims DoS Acknowledged
Description
With the
setClaimFeefunction the fee setter may assign anyclaimFeevalue. Therefore the fee setter may frontrun users who are attempting to withdraw their allocations and raise the fee to higher than the value that was sent so that the withdrawal reverts.Claims may also be trivially prevented by assigning a claim fee which is extremely high. Thus no user will be able to afford to claim their allocation. This can serve as a way to revoke allocations for those which should be non-revokable.
Recommendation
Consider assigning either a hard cap for the claim fee or an immutable cap which can be assigned at construction time.
-
L-03 Low feeCollector May DoS Claims DoS Acknowledged
Description
In the
MerkleVestercontract upon withdrawing the native fee is sent to thefeeCollector. However if thefeeCollectoris assigned to a contract which cannot accept ether then all withdrawals will be DoS’d.Recommendation
Be aware of this risk and clearly document it for users of Magna’s
MerkleVester.
No findings match.
More from Magna
All 9 reportsPut your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.