{"repo":"juancito-dev/multichain-auditor","free":true,"listed":false,"github":"https://github.com/juancito-dev/multichain-auditor","clone":"git clone https://github.com/juancito-dev/multichain-auditor.git","description":"Observations and tips checklist for auditing protocols on multiple chains 🧐","language":null,"stars":713,"topics":["auditing","ethereum","solidity","arbitrum","bsc","moonbeam","optimism","polygon","zksync","base"],"license":"MIT","category":"blockchain-web3","readme_excerpt":"Multichain Auditor Observations and tips for auditing protocols on multiple chains 🧐 ✍️ Open to Contributions If you see some error, or want to add an observation, please create an issue or a PR. References are greatly appreciated. You can also contact me on Twitter at @0xJuancito. 📜 Disclaimer Take the observations in this repository as a guideline and kickstarter to your findings. Judge the actual impact independently, and please do not use them as a tool to spam audit contests . Do your own research. Index - General Observations - Block time is not the same on different chains - Block production may not be constant - L2 Sequencer Uptime Feeds in Chainlink - Chainlink Price Feeds - AMM pools token0 and token1 order - Modified Opcodes - Support for the push0 opcode - Address Aliasing - tx.origin / msg.sender - tx.origin == msg.sender - Cross-chain message vulnerabilities - transfer, send and fixed gas operations - Gas fees - Frontrunning - Signature replay across chains - Hardcoded Contract Addresses - ERC20 decimals - Contracts Interface - Contracts Upgradability - Contracts may behave differently - Precompiles - zkSync Era - Differences from Ethereum General Observations Block time is not the same on different chains Block time refers to the time separating blocks. The average block time in Ethereum is 12s, but this value is different on different chains. Example: Example: OZ Wizard 💡 Look for hardcoded time values dependent on the block.number that may only be valid on","default_branch":null,"files":null,"tree":[],"storefront":"/r/juancito-dev","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/juancito-dev/multichain-auditor/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}