Assessment reportsPublic findings
Back to Zellic site
↗
Assessment reports>Orderly Network>Threat Model>setAllowedBroker
GeneralOverview
Findings
Critical (1)
High (4)
Medium (3)
Informational (1)
DiscussionAdditional checksOverall issues with some functionsThe `changeFeeCollector` does not revertThe `tokenHash` is not a hash from `tokenAddress`
Threat ModelWhat are threat models?AccountTypeHelper.solAccountTypePositionHelper.solCrossChainRelayUpgradeable.solFeeManager.solLedger.solLedgerComponent.solLedgerCrossChainManagerUpgradeable.solMarketManager.solOperatorManager.solOperatorManagerComponent.solSignature.sol
Vault.solchangeTokenAddressAndAllowdepositdepositToemergencyPauseemergencyUnpausesetAllowedBrokersetAllowedTokensetCrossChainManagerwithdraw
VaultCrossChainManagerUpgradeable.solVaultManager.sol
Audit ResultsSummary

Function: setAllowedBroker(byte[32] _brokerHash, bool _allowed)

This allows the owner of the contract to add new _brokerHash to the allowedBrokerSet or remove the existed.

Zellic © 2025Back to top ↑