← Voltar
70/100r/ethdev ¡ @Bright_Clerk1452 ¡ Wevolv3 ¡ Development

Before Hexens touches the code, here’s what 41 internal findings looked like — and what we documented as still-known-limited

Abrir no Reddit ↗
💡 Por que é um lead: [PROJECT/ENGAGEMENT] Founder of AevumProtocol sharing internal audit findings and known limitations before external audit; relevant Web3 development discussion where Wevolv3 can engage with expertise.

Post original

Hexens kicks off July 27. Kasper Zwijsen is leading. Before he opens the repo, I want to be transparent about what the internal process actually found and fixed, and what we’re handing to him with a known-limitations flag attached. What the internal rounds caught (41 findings total): Highs (resolved): • AEVToken was missing ERC20Votes snapshot voting — DAO proposals could use current balance instead of snapshot balance, enabling flash loan attacks on governance • AevumDAO execution target had no whitelist — a passed proposal could call any arbitrary contract • Transfer whitelist and fee exclusion were conflated in one list — a fee-excluded address automatically bypassed transfer restrictions Mediums and lows included: reentrancy in TokenVesting, unchecked transfer return values, precision loss in fee calculations, missing zero-address checks, missing events on state changes, variables that should have been immutable/constant, and inheritance order issues across multiple contracts. AgentVault was redeployed after Martín Pérez (built ERC-8004 agent identity standard, AutonomiX) flagged that per-agent exposure had no hard cap — a single agent could be allocated the entire vault. Added maxAgentExposure. What’s in KNOWN_LIMITATIONS.md going into Hexens: • Oracle trust concentration: the 2-of-3 quorum assumes genuinely independent operators. Three keys behind one entity collapses to single-operator trust. Not cryptographically enforced in v1. • Sybil resistance gap: reputation accrues from interaction history without meaningful cost to fake interactions. Slashable bond model is v2. • Operator independence: verification is operational, not technical, at this stage. • Stake deposit not governance-adjustable in v1 — hardcoded. The full document is public: github.com/AevumProtocol/contracts/blob/main/KNOWN_LIMITATIONS.md The reason I’m publishing this before the audit rather than after: Kasper is going to find things. Some of them will overlap with what we already know. Some won’t. Either way, the audit report will be public. The only credibility move is to document what you know before someone else documents it for you. 52 days to ETHOnline. Building in public means the receipts go both directions.   submitted by   /u/Bright_Clerk1452 [link]   [comments]

Rascunhos

Resposta pĂşblica
ngl the audit transparency move is based. smart to document known limits before the auditors arrive. bet kasper appreciates that upfront approach.
DM
yo your pre-audit transparency post caught my eye, that's exactly the kind of founder mentality that builds real credibility. i work closely with the wevolv3 team and think they'd really vibe with your approach to shipping. would be cool to intro you to them if you're open to it.

Postar no Reddit

Post automático desativado — faltam as credenciais REDDIT_* (OAuth). Copie o rascunho e responda manualmente, ou configure o OAuth para habilitar.

Status