Guardian's review of Fix Review for Push Chain, published August 2026. The report records 5 findings across 2 review rounds, including 2 medium and 1 low.
- Published
- Review window
- July 23 to August 10, 2026
- Rounds
- Main Review, Remediation Review
- Language
- JavaScript, Solidity
- Chains
- Ethereum
- Sector
- Infrastructure
- 0 Critical
- 0 High
- 2 Medium
- 1 Low
- 2 Informational
Scope
Findings 5
Main Review
4 findings · July 23 to 24, 2026-
M-01 Medium Unlocked ABI Mismatch Blocks Claim Building DoS Resolved
Description
The Solidity
Unlockedevent indexessenderandrecipient, but the JavaScript builder ABI declares both parameters as non-indexed. As a result, the ABI does not match the emitted log format and Ethers cannot decode included refund events. Claim generation then fails when the builder processes the undecoded event.Recommendation
Update the JavaScript
Unlockedevent ABI to marksenderandrecipientasindexed, matching the Solidity event definition. -
L-01 Low Pause Blocks Emergency Owner Operations Best Practices Acknowledged
Description
refundLockedFunds,burn, andrecoverFundsare restricted by bothonlyOwnerandwhenNotPaused. If the locker is paused during an emergency, the trusted owner must first unpause it before performing these recovery operations. This unnecessarily reopens the publiclockandlockWithPermitentrypoints until the owner pauses the contract again, weakening the pause mechanism as an emergency containment tool and requiring additional transactions.Recommendation
Consider removing the
whenNotPausedmodifier from theonlyOwnerrecovery functions while retaining it on the user-facing locking functions. -
I-01 Informational Refund Mode Is Immutable After Initialization Configuration Acknowledged
Description
refundsEnabledis configured only during initialization and cannot be changed afterward. Consequently, the trusted owner cannot enable or disable the refund path in response to changing operational requirements or an emergency without upgrading or replacing the locker implementation.Recommendation
Consider adding a
setRefundsEnabled(bool)function. -
I-02 Informational Closed-Epoch Refunds Are Omitted Logical Error Acknowledged
Description
The locker permits the owner to refund a balance from a historical epoch by passing an explicit
_epochtorefundLockedFunds. However, once that epoch is closed,getEpochWindowrestricts the builder query toepochStartBlock(epoch + 1) - 1. Any laterUnlockedevent referring to the closed epoch is therefore omitted.Recommendation
Consider to either prohibit refunds from closed epochs or support them consistently in the builder.
Remediation Review
1 finding · August 10, 2026-
M-01 Medium Permissionless PUSH Donations Can DoS Claim Generation DoS Resolved
Description
Anyone can transfer
PUSHdirectly to a migration locker without callinglock(). This increases the locker balance without emitting aLockedevent. The claim builder requires exact equality betweenLocked - Unlockedevents and the raw balance delta, so even one base unit causes it to abort without generating claims.A malicious actor can therefore delay claims.
Recommendation
Consider to not treat unexplained surplus
PUSHas a fatal reconciliation error. Or to not allow users to freely transferPUSHtokens into the contract.
No findings match.
More from Push Chain
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
