The Compound team engaged us to audit a new governance mechanism called Governor Bravo. The audited commit is f86c247f6f81e14f8e0fd78402653a0b8371266a in the proposed pull request, and the following files were included in scope: GovernorBravoDelegate.sol GovernorBravoDelegator.sol... structure. These contracts were audited by two auditors during the course of 5 days. Here we present our findings, in order of importance. Update: The Compound team has reviewed the issues and published fixes for them. The fixes can be found as pull requests in the following, separate github repository...
Low | Medium | High | Critical | Total | |
---|---|---|---|---|---|
Not fixed | - | - | - | - | 0 |
Fixed | 5 | 2 | - | - | 7 |
Total | 5 | 2 | 0 | 0 | 7 |
# | File Name |
---|---|
1 | contracts/Governance/GovernorBravoDelegator.sol |
2 | contracts/Governance/GovernorBravoDelegate.sol |
3 | contracts/Governance/GovernorBravoInterfaces.sol |