Assessment reportsPublic findings
Back to Zellic site
↗
Assessment reports>Chainflip Backend>Threat Model>Pallet: cf-lp
GeneralOverview
Findings
Critical (1)
High (1)
Medium (1)
DiscussionLack of broker fee limitsERC-20 transfer reversions result in stuck fundsType conversion could lead to fund loss
Threat ModelWhat are threat models?
1-cf-lpPallet: cf-lpFunction: `request_liquidity_deposit_address`Function: `withdraw_asset`Function: `register_lp_account`Function: `register_liquidity_refund_address`
2-cf-pools3-cf-swapping4-cf-witnesser5-engine
Audit ResultsSummary

Pallet: cf-lp

The cf-lp pallet is responsible for handling registration for the liquidity-provider role as well as deposits and withdrawals.

Zellic © 2025Back to top ↑