From my personal perspective:
- Great to see more security reviews, and especially formal verification.
- This finding mostly shows that smart contract developers can write bugs if they aren't careful.
- The core EOS token contract doesn't appear to be vulnerable in this way.
- If you're going to implement a token on an EOSIO Software based blockchain, you should either use the native token, or be a good programmer and guard against over- and under-flow bugs.
- Great to see a security-minded firm like LianAn Tech bringing both testing/verification as a service and pre-tested templates to the growing EOS community.
Thank you EOS Cannon and LianAn Tech.