Description:
Impact: The library prb-math documents that it is not audited by a security researcher. This means its more risky to
rely on this library.
Proof of Concept:
https://github.com/hifi-finance/prb-math#security The contracts have not been audited by a security researcher.
https://github.com/PaulRBerg/prb-math/pull/227 one of the issues, and the owner of the library say "Just wanted to say
that I unfortunately don't and won't have time to review this in the near future."
this was another issue that fixed after 9 month.
Recommended Mitigation:
Consider (crowdsourcing) an audit for prb-math
use another library
Referaces :
https://solodit.xyz/issues/m-10-prb-math-not-audited-code4rena-tracer-tracer-git
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.