Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
  • DIRECTORY
  • CRYPTO
    • ETHEREUM
    • BITCOIN
    • ALTCOIN
  • BLOCKCHAIN
  • EXCHANGE
  • TRADING
  • SUBMIT
Crypto Flexs
Home»HACKING NEWS»Сow Protocol: ComposableCoW and ExtensibleFallbackHandler Audit Summary
HACKING NEWS

Сow Protocol: ComposableCoW and ExtensibleFallbackHandler Audit Summary

By Crypto FlexsDecember 15, 20233 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Сow Protocol: ComposableCoW and ExtensibleFallbackHandler Audit Summary
Share
Facebook Twitter LinkedIn Pinterest Email

CoW Swap is the first trading interface built on the CoW protocol. CoW Swap is a Meta DEX aggregator that allows you to buy and sell tokens using gasless orders, settled peer-to-peer between users or settled with on-chain liquidity sources, while protecting against MEV.

cow protocol We performed a security review of ComposableCoW and ExtensibleFallbackHandler leveraging Ackee Blockchain, with total time donations as follows: 8 engineering days in the period between July 18th and July 28, 2023.

methodology

We use static analysis tools, namely wake up. We then took a closer look at the logic of the contract. For testing we wake up Test framework. During the review process, we paid special attention to the following:

  • replay attack
  • Signature Verification
  • Payload manipulation
  • Possible re-entry detection
  • Verify that the system’s calculations are correct
  • Accuracy of data encoding/decoding
  • ERC-1271 compliance
  • I’m looking for common problems like data validation.

range

The audit was conducted in the following scope:

A review has been performed on the specified commit. Revision 1.0:

  • 27ec79b For ComposableCow
  • 11273c1 For ExtensibleFallbackHandler

Revision 1.2 was done in the ComposableCow commit. bd2634dThe ExtensibleFallbackHandler commit has not changed since Revision 1.1.

result

Here we have our result.

critical severity

C1: StopLoss arithmetic mismatch

Severity High

No high severity issues were found.

medium severity

M1: Oracle data validation

low severity

L1: Constructor data validation

warning severity

W1: GPv2Order data tampering

W2: Revert condition mismatch

W3: Vulnerable MerkleProof library

W4: GoodAfterTime order is missing recipient address.

Information Severity

I1: Unnecessary SafeMath

I2: Missing cabinet organization

I3: Error in documentation

I4: Specify TradeAboveThreshold order recipient name

I5: mismatch error

I6: Commented code

I7: Inconsistent naming

conclusion

The review resulted in 14 findings ranging in severity from informational to critical. important issue C1: StopLoss arithmetic mismatch Modified according to our recommendations and M1: Oracle data validation The issue has been implemented correctly (revision 1.2).

Other issues include low-severity data validation, warnings, and informational findings, which are recommendations rather than issues. The overall code quality and architecture are professional. The entire project is well documented, with in-code NatSpec documentation and detailed explanations.

Ackee Blockchain recommends the CoW protocol.

  • To add Oracle data validation
  • Know about zero address verification
  • To unify syntax and naming
  • We resolve all reported issues.

As of revision 1.2, the L1: constructor data validation issue has been acknowledged and all other issues have been fixed.

Ackee blockchain is full COW Protocol You can find the audit report with a more detailed description of all findings and recommendations. here.

We were happy to give our thanks. cow protocol And I’m looking forward to working with them again.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Cryptocurrency romance scams are now not only a consumer scam, but also a national threat.

November 16, 2025

As RWA momentum accelerates, BlackRock’s BUILD launches on the BNB chain.

November 14, 2025

Mastering Wake Printers for Solidity Security Analysis

November 12, 2025
Add A Comment

Comments are closed.

Recent Posts

Strategy to expand corporate holdings amid Bitcoin slump

November 17, 2025

Lite Strategy Reports First Quarter Fiscal Year 2026 Results; Highlights Successful Launch of $100M Litecoin Treasury Strategy and Movement into Active Capital Market Operations

November 17, 2025

The First Self-Sovereign AI Agent For Using And Automating Any Smart Contract

November 17, 2025

SGX Derivatives Breaks New Ground With Institutional-grade Crypto Perpetual Futures

November 17, 2025

Blockchain For Good Alliance (BGA) Recognized Groundbreaking Blockchain Projects Advancing The SDGs At 2025 Forum

November 17, 2025

Phemex Celebrates Its 6th Anniversary With 66% User Growth And Shared Vision

November 17, 2025

Aster Launches Stage 4 Airdrop And $10M Trading Competition To Accelerate Ecosystem Growth

November 17, 2025

BYDFi Joins CCCC Lisbon 2025 As Sponsor, Empowering Creators And Web3 Education

November 17, 2025

Building the first regulated esports platform for fair, skills-based competition in Europe

November 17, 2025

Deribit And SignalPlus Launch 2025 Trading Competition, Featuring A $450,000 USDC Prize Pool

November 17, 2025

Cryptocurrency romance scams are now not only a consumer scam, but also a national threat.

November 16, 2025

Crypto Flexs is a Professional Cryptocurrency News Platform. Here we will provide you only interesting content, which you will like very much. We’re dedicated to providing you the best of Cryptocurrency. We hope you enjoy our Cryptocurrency News as much as we enjoy offering them to you.

Contact Us : Partner(@)Cryptoflexs.com

Top Insights

Strategy to expand corporate holdings amid Bitcoin slump

November 17, 2025

Lite Strategy Reports First Quarter Fiscal Year 2026 Results; Highlights Successful Launch of $100M Litecoin Treasury Strategy and Movement into Active Capital Market Operations

November 17, 2025

The First Self-Sovereign AI Agent For Using And Automating Any Smart Contract

November 17, 2025
Most Popular

Morgan Stanley: Spot Bitcoin ETF Approval Is a ‘Potential Paradigm Shift’ in Global Perspectives on Cryptocurrencies

January 13, 2024

According to cryptocurrency analysts, Bitcoin is poised to hit all-time highs in the next phase. His goals are:

January 18, 2025

Uniswap has received a lawsuit warning from the SEC.

April 11, 2024
  • Home
  • About Us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
© 2025 Crypto Flexs

Type above and press Enter to search. Press Esc to cancel.