Audit report published Mar 2025. Solidity.
| Severity | Count |
|---|---|
| Medium | 3 |
| Low | 3 |
| Informational | 5 |
| Total | 11 |
This is the detailed issue write-up from Safe Edges' March 2025 review of Clique's token distribution and vesting contracts (CliqueLock, Distributor and CliqueDistributorManager). It sets out eleven issues, three Medium, three Low and five Informational, with the code and recommended fixes for each. It does not record resolution statuses. The fix statuses for the same eleven findings are recorded in the companion final report, Safe-Edges_Clique_b3-Distribution-and-Vesting_2025-03.
M-01 Incorrect totalPieces calcualtion in CliqueLock:calculateClaimableAmount can leads to unevenly vesting amount distributionM-02 Anyone can initiate claim of any stream by using just their streamId in CliqueLock:claim functionM-03 CliqueDistributorManager:createDistributor should expilicit check for signature non-malleabilityL-01 Excessive sent ether would not be refunded to the user in Distributor:claim functionL-02 Missing fee validation checks in Distributor:setFee functionL-03 Lack of multiple validations in CliqueLock:_createStream before creating stream leads to spam creations.I-01 Twice imports of ECDSA library in CliqueDistributorManager.solI-02 Missing check for signature usage in CliqueDistributorManager:createDistributor can leads to same signature being used multiple timesI-03 Consider using SafeERC20 for IERC20 to make the transfer more secure.I-04 Missing checks for address(0) when assigning values to address state variablesI-05 Remove Unused Custom Error to save more gasSend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.