Skip to content
Request an audit

‹ All findings

Verifier::checkQuorum() returns false with more than 3 signers

Low/InfoVertex·by the Three Sigma team·Hybrid orderbook DEX·3rd April 20243S-Vertex-L01

Description

The signerBitmask is hardcoded to 7 when calling requireValidSignature(), meaning that nSigned would be incremented at most 3 times in checkQuorum() as 7 = 00000111.

Consequently, if there are more than 3 signers added in the Verifier contract, Verifier::checkQuorum() will always return false in the following scenarios:

  • nSigner >= 4 and nSigned <= 2
  • nSigner >= 6 and nSigned <= 3

Recommendation

Make signerBitmask dynamic.

Status

Addressed in #38bbe76.