Security Audit Flags High-Risk Reentrancy and Admin Control Flaws in Poloniex Contracts
A security audit dated October 26, 2023, conducted by a senior DeFi research team, reviewed the Poloniex protocol's smart contracts across Ethereum and Layer 2 networks, where roughly $1.49 billion in assets are locked. Auditors identified a high-risk vulnerability in the legacy withdrawal function, which lacks a robust reentrancy guard and could be exploited through malicious ERC-20 token callbacks. A medium-risk flaw was also found in the deposit function, which interacts with external tokens without a nonReentrant modifier, leaving non-standard tokens able to trigger reentrant calls. Critically, the protocol's owner role holds unchecked power to pause withdrawals and alter fee parameters, with no multi-signature enforcement found in the deployed contract bytecode. The audit assigned an overall risk score of 7.2 out of 10, citing the high TVL and centralized admin privileges as the primary concern.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in