docs: Olympix security-report presentation - #387
Conversation
|
Thank you for the PR.
|
|
Hey @rya-sge , thanks for your response. Did you also get a chance to look at the mutation test results? What did you think about those? |
|
Hello @robotrobo , Thank you for your message and for running the tool on CMTAT. Regarding mutation testing, I have found them interesting and we have added one supplementary test, see 8d3029d17e0c57db4fe192ff4ab878734544b0c5 If your company agrees, it would be great if we can put the report (the report only) with our feedback file in the security tool directory of CMTAT. Could it be possible ? Best! |
What this is
Three independent Olympix runs against CMTAT, collected into one reviewable page. Full write-up (with tables, collapsibles, and links to every artifact) lives in
docs/olympix/report.md.At a glance
High findings
forcedBurn—forcedBurnskips the validation path and can destroy a frozen holder's tokens afterdeactivateContract(). Runnable PoC.setFrozenTokenscan exceed balance; over-freezingaddress(0)can globally brick minting.Layout
Session IDs and reproducibility details are in the report footer.