This is the report from a security audit performed on ZAC Finance by MrCrambo.
The audit focused primarily on the security of ZAC Finance smart contract.
In total, 2 issues were reported including:
-
0 high severity issues.
-
0 medium severity issues.
-
0 owner privilegies issues.
-
2 low severity issues.
There are no zero address checking in functions transfer
and transferFrom
and also total supply will be calculated as the difference between all the tokens and zero address balance.
We recommend to add burn
function for burning extra tokens and to add zero address checking in functions transfer
and transferFrom
.
-
It is possible to double withdrawal attack. More details here
-
Lack of transaction handling mechanism issue. WARNING! This is a very common issue and it already caused millions of dollars losses for lots of token users! More details here
Add into a function transfer(address _to, ... )
following code:
require( _to != address(this) );
There is no Approval
event emitted after the transferFrom
function will be executed. But it would be better to call this event, because allowed transfer amount will be changed.
Smart contract contains only low severity issues and could be deployed on mainnet without any threats to investors.