40,000 USDC
View results
Submission Details
Severity: medium
Valid

Zero address check

Summary

Vulnerability Details

The contract lacks zero address checks during the deployment of a new escrow from the factory contract for tokenContract & seller.

Impact

As per the statement made in Discord "Arbiter can be zero address". So, in the case of the seller's address also being a zero address. The fund deposited by the buyer will be stuck in the contract forever.

Tools Used

Manual Review.

Recommendations

Add a zero address check to the function.

Support

FAQs

Can't find an answer? Chat with us on Discord, Twitter or Linkedin.