Audit report published Oct 2023. Solidity.
| Severity | Count |
|---|---|
| High | 2 |
| Medium | 1 |
| Low | 2 |
| Total | 5 |
Safe Edges reviewed Qoodo's vesting contract. Five issues were identified: two High, one Medium and two Low. The High issues were a missing owner check on addVestingSchedule, which let anyone create a schedule with unlimited tokens, and a revoke path that left unclaimed tokens stranded. Qoodo fixed all five.
H-01 Missing refund token parameter in revoke function which causes a loss of funds — ResolvedH-02 In addvesting schedule function missing only owner modifier. So any user can create a vesting schedule with infinite tokens. It’s a direct loss of funds — ResolvedM-01 Missing zero check in payee address — ResolvedL-01 Not follow CEI pattern in claim function — ResolvedL-02 Missing event in claim function — ResolvedSend the repository and a commit hash through the contact form, message @bugtester25 on Telegram, or book a 30-minute scoping call. 200+ protocols audited · $4B+ secured · 0 hacks post-audit. Prefer email? info@safeedges.in.