Executive Summary
Bug Hunter examined AAVE's yield farming contracts for vulnerabilities and implementation risks. This page summarizes the analysis.
Engagement Overview and Scope
A codebase from project AAVE was reviewed for security vulnerabilities by Bug Hunter with the following details:
- GitHub Repository: https://github.com/aave/protocol-v2
- Commit hash:
12d97f9f13a3f04c206c6a72b93c23126b869572
Bug Hunter reviewed the following files:
LendingPoolAddressesProvider.solLendingPoolAddressesProviderRegistry.solIAaveIncentivesController.solIChainlinkAggregator.solIERC20.solIERC20Detailed.solIExchangeAdapter.solILendingPool.solILendingPoolAddressesProvider.solILendingPoolAddressesProviderRegistry.solILendingRateOracle.solIPriceOracle.solIPriceOracleGetter.solIReserveInterestRateStrategy.solISwapAdapter.solIUniswapExchange.solDefaultReserveInterestRateStrategy.solLendingPool.solLendingPoolCollateralManager.solLendingPoolConfigurator.solLendingPoolStorage.solReserveConfiguration.solUserConfiguration.solGenericLogic.solReserveLogic.solValidationLogic.solErrors.solHelpers.solMathUtils.solPercentageMath.solContext.solIERC20DetailedBytes.solAToken.solIncentivizedERC20.solStableDebtToken.solVariableDebtToken.solDebtTokenBase.solIAToken.solIScaledBalanceToken.solIStableDebtToken.solIVariableDebtToken.sol
Summary of Findings
The uncovered vulnerabilities in the codebase during the security review are summarized in the table below:
| Severity | Count |
|---|---|
| High | 0 |
| Medium | 4 |
| Low | 21 |
FULL REPORT