Giter Club home page Giter Club logo

2023-05-perennial's Introduction

Perennial contest details

Q&A

Q: On what chains are the smart contracts going to be deployed?

Perennial is deployed on Ethereum and Arbitrum mainnets


Q: Which ERC20 tokens do you expect will interact with the smart contracts?

DSU and USDC


Q: Which ERC721 tokens do you expect will interact with the smart contracts?

None


Q: Which ERC777 tokens do you expect will interact with the smart contracts?

None


Q: Are there any FEE-ON-TRANSFER tokens interacting with the smart contracts?

None


Q: Are there any REBASING tokens interacting with the smart contracts?

None


Q: Are the admins of the protocols your contracts integrate with (if any) TRUSTED or RESTRICTED?

TRUSTED


Q: Is the admin/owner of the protocol/contracts TRUSTED or RESTRICTED?

Protocol admin (Controller.owner): TRUSTED


Q: Are there any additional protocol roles? If yes, please explain in detail:

Product Coordinator - these are owners of the products who can update product parameters


Q: Is the code/contract expected to comply with any EIPs? Are there specific assumptions around adhering to those EIPs that Watsons should be aware of?

None


Q: Please list any known issues/acceptable risks that should not result in a valid finding.

Malicious product coordinators can steal user funds from their own product. We are aware that malicious coordinators have a large amount of power with respect to funds deposited towards their products, however, if they can adversely affect other products/collateral outside their product we want to be are of this.


Q: Please provide links to previous audits (if any).

https://drive.google.com/file/d/1WPPDUAAxgQhvY38jiKutRogqQoPtoBKF/view?usp=drivesdk

https://github.com/equilibria-xyz/perennial-mono/tree/master/packages/perennial/audits


Q: Are there any off-chain mechanisms or off-chain procedures for the protocol (keeper bots, input validation expectations, etc)?

Off-chain liquidators, OpenZeppelin defender tasks which periodically sync the vaults if they get far out of balance


Q: In case of external protocol integrations, are the risks of external contracts pausing or executing an emergency withdrawal acceptable? If not, Watsons will submit issues related to these situations that can harm your protocol's functionality.

We want to be aware of issues that might arise from Chainlink or DSU integrations


Audit scope

root @ 914838c1cb2532325ecf5659807f9fca61d635e9

perennial-mono @ b06d5145db62a312dd88dfcafef0f8e2166c5e32

2023-05-perennial's People

Contributors

sherlock-admin avatar frimoldi avatar hrishibhat avatar

Stargazers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.