Skip to content

Instantly share code, notes, and snippets.

What would you like to do?


This is the report from a security audit performed on LCX by MrCrambo.

The audit focused primarily on the security of LCX smart contract.

In scope



In total, 4 issues were reported including:

  • 0 high severity issues.

  • 0 medium severity issues.

  • 3 owner privilegies issues.

  • 1 low severity issues.

  • 0 notes.

Security issues

1. Owner privilegies

Severity: owner privilegies


  • Owner can change LCXToken contract address any time and to any not audited contract. Line 241.
  • Owner can revoke any address vested tokens and send himself his tokens. Line 367.
  • Owner can change vesting contract any time and to any not audited contract. Line 561.

2. Known vulnerabilities of ERC-20 token

Severity: low


  1. It is possible to double withdrawal attack, because increaseAllowance and decreaseAllowance functions call inside of them approve function, but not add or decrease value. More details here
  2. Lack of transaction handling mechanism issue. More details here


Add into a function transfer(address _to, ... ) following code:

require( _to != address(this) );


Smart contract is free of serious issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.