Guardian's review of IERC7802 Support for USDT0, published March 2025. The report records 4 findings, including 4 informational.
- Published
- Review window
- March 5, 2025
- Language
- Solidity
- Chains
- Ethereum, Arbitrum, Ink, Hyperliquid, Polygon, Monad, Solana, Stellar
- Sector
- Stablecoins
- 0 Critical
- 0 High
- 0 Medium
- 0 Low
- 4 Informational
Scope
Findings 4
-
I-01 Informational mint Function Is Now Exposed Unexpected Behavior Acknowledged
Description
The
mintfunction is no longer overridden in theTetherTokenOFTExtensionandArbitrumExtensionV2contracts, as a result theownerpermissionedmintfunction from the baseTetherTokencontract is available to call.Recommendation
Consider if this is expected. Be aware that this mint function should never be called under normal circumstances, as the minted USDT0 would not have backing USDT in the OAdapter contract on Ethereum.
-
I-02 Informational Upgrades Should Happen Atomically Warning Acknowledged
Description
When upgrading the OFT and Token contracts to include the
IERC7802support, care should be taken to upgrade both contracts in rapid succession and ideally atomically in the same transaction.If the receipt transaction of a USDT0 bridge were to occur in a state where only one of the OFT and Token contracts have been upgraded, then the bridge receipt would fail and would be required to be retried through the
EndpointV2contract by calling thelzReceivefunction.Recommendation
Consider deploying the upgrades with a
multicallso that it is impossible to disrupt any active bridges. -
I-03 Informational Lacking supportsInterface Interfaces Warning Acknowledged
Description
In the
ArbitrumExtensionV2andTetherTokenOFTExtensioncontracts thesupportsInterfacefunction indicates that theIERC7802andIERC165interfaces are supported by the contract.The contracts do support several other ERC standards which are not indicated by the
supportsInterfacefunction:- ERC20
- ERC2612
- ERC3009
However none of the EIPs associated with these ERCs require or mention inclusion with
IERC165, therefore it is not necessary to list them in thesupportsInterfacefunction.Recommendation
This finding serves only to document this fact, be aware of this behavior and consider if it is as intended.
-
I-04 Informational Upgrade Warning Warning Acknowledged
Description
The upgrade of existing USDT0 token contracts to include
IERC7802support may introduce unexpected changes to the existing deployments.For example, the
TetherTokenOFTExtensioncontract currently deployed on Ink does not have the_EIP712NameHashoverride which currently exists in the latest version of this contract.If the returned value of the
name()function were different than the name used in the original_EIP712NameHashvalue, then such an upgrade would invalidate signatures that were made in the past under the previous domain.This is however not the case for the Ink deployment as the
name()result is the same as the name hash used in the_EIP712NameHashfunction.Changes like this may be unexpected and should be carefully examined for each chain on which an upgrade is performed.
Recommendation
Be aware of potentially unexpected code changes that may be introduced during upgrades for
IERC7802support.
No findings match.
More from USDT0
All 20 reportsPut your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
