Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · September 2024

Upgradeable Token

for Zap

The Zap team engaged Guardian to review the security of its upgradeable token contract. On the 30th of September 2 auditors reviewed the source code in scope.

Published
Language
Solidity
Chains
Base
Sector
Tokens
  • 0 Critical
  • 0 High
  • 0 Medium
  • 1 Low
  • 0 Informational

1 acknowledged

Scope

Overview

The Zap team engaged Guardian to review the security of its upgradeable token contract. On the 30th of September 2 auditors reviewed the source code in scope.

Findings 1

  1. L-01 Low Security Contract Suggestion Security Contact Acknowledged
    Location
    ZapToken.sol

    Description

    The ZapToken contract does not include a security contact in it’s NatSpec.

    This is a best practice as it allows the deployer to direct communication of potential vulnerabilities, reducing the risk of a miscommunication or lack of reporting when a security vulnerability arises.

    Recommendation

    Consider adding a security contact in a NatSpec comment above the ZapToken contract. For example, the @custom:security-contact XXX@XXX.com convention is recommended.

    Resolution

    ZAP Team: Acknowledged.

More from Zap

  1. Node Sale

    46 findings8 critical · 13 high 46 findings: 8 critical, 13 high, 8 medium, 17 low

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote