Security Audit Report: Reentrancy & Access Control Review: Portal
Security Audit Report: Reentrancy & Access Control Review: Portal Target Protocol : Portal (TVL: $1947.2M) Security Audit Report: Reentrancy & Access Control Review Protocol: Portal Scope: Core Smart Contracts (Ethereum Mainnet & L2s) TVL Context: $1,947.2M Date: October 26, 2023 Auditor: Senior DeFi Security Research Team 1. Executive Summary This report presents the findings of a targeted…
The security audit report on Portal protocol's smart contracts highlights critical vulnerabilities and suggests immediate remediation before scaling.
The first major issue is a potential cross-function reentrancy attack vector present in the withdraw and rebalance functions. The audit found that the current code structure doesn't enforce a global reentrancy guard, making it possible for a malicious contract to re-enter the withdraw function before state variables are updated. This could allow attackers to withdraw more funds than they're entitled to, or drain the protocol's reserves, potentially resulting in a total loss of funds given the protocol's $1.9 billion TVL.
Secondly, there are inconsistencies in the access control mechanisms. Some administrative functions use onlyOwner, while others use onlyRole. However, the role assignment logic in the governance contract allows the current owner to grant admin privileges to any address without restrictions. An attacker who compromises the owner's key could manipulate protocol parameters, such as redirecting fees to their wallet or manipulating price feeds for fraudulent activities.
Lastly, the report points out missing checks for msg.sender in certain internal functions that modify critical state variables. While the current call graph appears secure, future code additions could potentially expose these functions to unauthorized callers. This could lead to user funds being manipulated or lost if malicious actors call these functions with invalid sender addresses.
The audit emphasizes the need for immediate action on these vulnerabilities due to the protocol's substantial TVL and the potential scale of damage. Recommendations include implementing a global reentrancy guard, enforcing a more consistent access control system, and improving state validation. These fixes are crucial to maintaining the protocol's integrity and securing investor funds.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.