Organization
- @ParcelHQ
Engagement Type
Cantina Reviews
Period
-
Repositories
Researchers
DAO Payroll Infrastructure Security Review of Parcel
Parcel provides a user-friendly interface for DAOs to automate one-off and recurring contributor payouts. The system is built to integrate with Safe wallets, supporting multi-token streams, signature validation, and configurable access roles to manage compensation flows with transparency and control.
To secure this core functionality, Parcel engaged Cantina for a security audits review of its payroll system. The audit covered critical logic including token retrieval validation, Safe address signing, nonce handling, and balance reconciliation in executePayroll()
—addressing risks related to frontrunning, replay, and token mixing.
Cantina also supports DAO infrastructure with extended protections through bug bounty programs, crowdsourced security competitions, and multisig security, helping teams like Parcel maintain secure contributor payments at scale.
Findings
High Risk
5 findings
5 fixed
0 acknowledged
Medium Risk
6 findings
5 fixed
1 acknowledged
Low Risk
6 findings
5 fixed
1 acknowledged
Informational
20 findings
16 fixed
4 acknowledged
Gas Optimizations
13 findings
11 fixed
2 acknowledged