Security audit flags critical reentrancy and access control flaws in Grove Finance
A senior DeFi security research team published an audit report on October 26, 2023, reviewing Grove Finance, a yield optimization protocol with approximately $2.33 billion in Total Value Locked across Ethereum Mainnet and Layer 2 deployments. The audit identified two critical and three high-severity findings centered on reentrancy vulnerabilities and weak access control mechanisms. Key critical flaws include an unguarded cross-chain message function in GroveBridgeAdapter.sol that could allow attackers to double-spend bridged assets, and an admin role in GroveAdmin.sol that combines upgrade and pause powers, enabling a compromised key to drain all user funds. A high-severity issue was also found in GroveYieldDistributor.sol, where yield distribution logic violates the Checks-Effects-Interactions pattern, exposing the protocol to repeated reentrancy attacks. Given the protocol's massive TVL, auditors rated the overall risk as high and warned that even low-probability exploits could result in catastrophic financial losses.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in