Baseline engaged Guardian to review the security of their BToken Updates. From the 24th Of October to the 27th of October, a team of 3 auditors reviewed the source code in scope.
- Published
- Language
- Solidity
- Chains
- Blast
- Sector
- Token launches
- 0 Critical
- 0 High
- 4 Medium
- 4 Low
- 0 Informational
Scope
Overview
Baseline engaged Guardian to review the security of their BToken Updates. From the 24th Of October to the 27th of October, a team of 3 auditors reviewed the source code in scope.
Findings 8
-
M-01 Medium Lack Of Policy Permissions Access Control Acknowledged
Description
migrateBTokenfunction in the BPOOL module is apermissionedfunction and it should be called via policies. However, none of the policies have permission to call this function.Recommendation
Consider which policy is expected to call this function and add the function’s selector to the
requestPermissionsprocess.Resolution
Baseline Team: Acknowledged.
-
M-02 Medium Incorrect BPOOL Locked State Logical Error Resolved
Description
ERC20 features are moved from
BPOOLto separateBTokencontract with the current update. However, thelockedstatus still remains in the BPOOL contract, in addition to theBTokencontract, creating an asymmetry.The
setTransferLockfunction correctly updates thelockedstatus of theBTokencontract, but there is no mechanism to update thelockedstatus in BPOOL. SinceBPOOL.lockedis set to true in the constructor, it will always appear locked.This will lead to discrepancies for integrators who read
BPOOL.lockedinstead ofBPOOL.bToken.locked.Recommendation
Remove the
lockedfrom theBPOOLand use it only from theBToken.Resolution
Baseline Team: The issue was resolved in commit 9e4a37e.
-
M-03 Medium Exit Loop Before Borrow Operation Logical Error Resolved
Description
In the function
_loop, an early exit occurs ifminimumCollateralis hit. This is called after the borrow operation.However, if
_bAssetsInis too small, the borrow operation could revert as no new principal is transferred out. This would result in the entirereheatoperation reverting.Recommendation
The early exit for
minimumCollateralshould be done before the borrow operation.Resolution
Baseline Team: The issue was resolved in commit 4e6670a.
-
M-04 Medium probabilityDenominator Increased If No Swap Logical Error Acknowledged
Description
In the
reheatfunction, the probability denominator is incremented with each successful hit to make future hits less likely.However, when
reserveSize = 0, no swap occurs despite the successful hit, but the probability denominator is still incremented.This reduces the likelihood of true hits (where actual swaps occur) since hits that result in no swaps still affect the probability, making legitimate hits less frequent.
Recommendation
Consider incrementing the probability denominator only if a swap occurs.
Resolution
Baseline Team: Acknowledged.
-
L-01 Low Lack Of Validation In setController Warning Acknowledged
Description
The
setControlleris a critical function that hands control of mint/burn ability to a new address. Given the importance of the function, consider validating the new controller address to avoid handing control to an unintended address.Recommendation
Validate that
_controlleris not a zero address and consider implementing a two-step handover process.Resolution
Baseline Team: Acknowledged.
-
L-02 Low Remove Console2 Imports Informational Resolved
Description
console2imports were found in:LOOPS.v1.solBaselineInit.solLoopFacility.solMarketMaking.sol
Recommendation
Remove the import statements.
Resolution
Baseline Team: The issue was resolved in commit 9e4a37e.
-
L-03 Low Misleading Developer Comments Informational Resolved
Description
Comments on the function
dropand_decrementSweepTickindicate that tick will be moved exactly one tick spacing lower. However, with the revised_getDecrementedSweepTick, it is possible to move the tick by more than one tick spacing.Additionally, the “transfer any surplus collateral back to the
bAssetcontract” comment in the LOOPS contract is incorrect, and it should be “transfer any surplus collateral back to the BPOOL contract”.Recommendation
Update developer comments.
Resolution
Baseline Team: The issue was resolved in commit 4e6670a.
-
L-04 Low Unexpected Behavior During High Premiums Logical Error Acknowledged
Description
When the premium between the active price and BLV is too high, no reserves are swapped during reheat due to capital inefficiency.
However,
bAssetsare still converted to reserves via borrowing from theCreditFacilityand defaulting on self, which burnsbAssetcollateral.Burning tokens can create upward pressure on the price, further increasing the premium, which is undesirable.
Recommendation
If the premium is too high, consider gracefully exiting without performing any borrowing or swapping actions.
Resolution
Baseline Team: Acknowledged.
No findings match.
More from Baseline Markets
All 12 reports-
Mercury, Round 3
109 findings4 critical · 9 high 109 findings: 4 critical, 9 high, 28 medium, 33 low, 35 informational -
AMM, Round 2
47 findings4 critical · 14 high 47 findings: 4 critical, 14 high, 8 medium, 13 low, 8 informational -
AMM
54 findings3 critical · 6 high 54 findings: 3 critical, 6 high, 13 medium, 11 low, 21 informational -
Fixed Supply
34 findings4 high 34 findings: 4 high, 10 medium, 20 low
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
