Audit Open Original ↗
Propeller Heads Turbine
Type
Security review
Client
Propeller Heads
Date
2026-03
Domain
AppSec
Effort
8 wks
Section
Technology Product Reviews
Trail of Bits's security review of Propeller Heads (Mar 2026) identified 21 issues: 3 high, 6 medium, 4 low, and 8 informational.
Findings · 21
- 1 Documentation for running tests needs to be updated Informational
- 2 serialize_struct argument does not match number of serialize_field calls Informational
- 3 PermitSingle and PermitBatch’s From implementations can panic in U48::from Informational
- 4 u256_to_naive_datetime can produce values before UNIX epoch Low
- 5 Invalid bit-length comparison in reduce_precision Medium
- 6 Recursive price filtering allows oracle threshold bypass Medium
- 7 SIWE message version field is not validated Low
- 8 U256 arithmetic errors silenced with unwrap_or Informational
- 9 Authentication credentials leak when transmitted over unencrypted HTTP Medium
- 10 Potential integer overflow in function scale_up_input High
- 11 ECDSA signature malleability Low
- 12 Missing validation of user balance vector length Low
- 13 Missing block number validation in pool state updates Informational
- 14 Race conditions are present in filesystem operations Informational
- 15 Unable to safely change hook address High
- 16 Unbounded intent array enables denial of service of settlement system High
- 17 Nonstandard ERC-20 tokens cause swap failures due to unsafe transfer checks Medium
- 18 Insufficient pre-execution validation enables single-user actions to cause batch settlement failures Medium
- 19 Remove liquidity operations lack slippage protection, enabling unfavorable token ratios Medium
- 20 Off-by-one-second discrepancy in speedbump enforcement between on-chain and off-chain paths Informational
- 21 Missing minimum buy amount validation allows users to receive less than specified minimum Informational
Findings extracted from the published report PDF. See the full report below for details and remediation.
Related