Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · August 2026

Fix Review

for Push Chain

Guardian's review of Fix Review for Push Chain, published August 2026. The report records 5 findings across 2 review rounds, including 2 medium and 1 low.

Published
Review window
July 23 to August 10, 2026
Rounds
Main Review, Remediation Review
Language
JavaScript, Solidity
Chains
Ethereum
Sector
Infrastructure
  • 0 Critical
  • 0 High
  • 2 Medium
  • 1 Low
  • 2 Informational

2 resolved · 3 acknowledged

Scope

Findings 5

Main Review

4 findings · July 23 to 24, 2026
  1. M-01 Medium Unlocked ABI Mismatch Blocks Claim Building DoS Resolved
    Round
    Main Review

    Description

    The Solidity Unlocked event indexes sender and recipient, but the JavaScript builder ABI declares both parameters as non-indexed. As a result, the ABI does not match the emitted log format and Ethers cannot decode included refund events. Claim generation then fails when the builder processes the undecoded event.

    Recommendation

    Update the JavaScript Unlocked event ABI to mark sender and recipient as indexed, matching the Solidity event definition.

  2. L-01 Low Pause Blocks Emergency Owner Operations Best Practices Acknowledged
    Round
    Main Review

    Description

    refundLockedFunds, burn, and recoverFunds are restricted by both onlyOwner and whenNotPaused. If the locker is paused during an emergency, the trusted owner must first unpause it before performing these recovery operations. This unnecessarily reopens the public lock and lockWithPermit entrypoints until the owner pauses the contract again, weakening the pause mechanism as an emergency containment tool and requiring additional transactions.

    Recommendation

    Consider removing the whenNotPaused modifier from the onlyOwner recovery functions while retaining it on the user-facing locking functions.

  3. I-01 Informational Refund Mode Is Immutable After Initialization Configuration Acknowledged
    Round
    Main Review

    Description

    refundsEnabled is configured only during initialization and cannot be changed afterward. Consequently, the trusted owner cannot enable or disable the refund path in response to changing operational requirements or an emergency without upgrading or replacing the locker implementation.

    Recommendation

    Consider adding a setRefundsEnabled(bool) function.

  4. I-02 Informational Closed-Epoch Refunds Are Omitted Logical Error Acknowledged
    Round
    Main Review

    Description

    The locker permits the owner to refund a balance from a historical epoch by passing an explicit _epoch to refundLockedFunds. However, once that epoch is closed, getEpochWindow restricts the builder query to epochStartBlock(epoch + 1) - 1. Any later Unlocked event referring to the closed epoch is therefore omitted.

    Recommendation

    Consider to either prohibit refunds from closed epochs or support them consistently in the builder.

Remediation Review

1 finding · August 10, 2026
  1. M-01 Medium Permissionless PUSH Donations Can DoS Claim Generation DoS Resolved
    Location
    GLOBAL
    Round
    Remediation Review

    Description

    Anyone can transfer PUSH directly to a migration locker without calling lock(). This increases the locker balance without emitting a Locked event. The claim builder requires exact equality between Locked - Unlocked events and the raw balance delta, so even one base unit causes it to abort without generating claims.

    A malicious actor can therefore delay claims.

    Recommendation

    Consider to not treat unexplained surplus PUSH as a fatal reconciliation error. Or to not allow users to freely transfer PUSH tokens into the contract.

More from Push Chain

  1. Push Chain Migration

    19 findings 19 findings: 12 low, 7 informational

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote