The current audit is focused on the Portal token contract as well as associated token vesting features. In addition to a relatively straightforward token that is made for use in a cross-chain context, `TokenVestingLinear` and `TokenVestingSigmoid` are contracts designed to enable vesting the Portal token with a linear vesting schedule and a sigmoid vesting schedule respectively. Notably, the implementation of `TokenVestingLinear` aims to enable the participation of Solana users. Three medium-severity issues were found during the audit. 1. Under particular conditions, a schedule may be seeded twice; 1. An address may be minted to more than once during `PortalToken` deployment; 1. Privileged roles are quite powerful. Note also three undetermined-severity issues. We recommend addressing all the issues in this report. **Update**: All the issues have been addressed. However, we would like to note the remaining security issue in PTL-19. Care should be taken not to use the same message format in other contracts as this may lead to signature replay even on the same blockchain.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 15 | 2 | - | - | 17 |
Acknowledged | - | - | - | - | 0 |
Fixed | 3 | 1 | - | - | 4 |
| Total | 18 | 3 | 0 | 0 | 21 |
| # | File Name |
|---|---|
| 1 | src/TokenVestingLinear.sol |
| 2 | src/TokenVestingSigmoid.sol |
| 3 | src/PortalToken.sol |