Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · February 2025

bToken

for Baseline Markets

Baseline engaged Guardian to review the security of their BToken Updates. From the 24th Of October to the 27th of October, a team of 3 auditors reviewed the source code in scope.

Published
Language
Solidity
Chains
Blast
Sector
Token launches
  • 0 Critical
  • 0 High
  • 4 Medium
  • 4 Low
  • 0 Informational

4 resolved · 4 acknowledged

Scope

Overview

Baseline engaged Guardian to review the security of their BToken Updates. From the 24th Of October to the 27th of October, a team of 3 auditors reviewed the source code in scope.

Findings 8

  1. M-01 Medium Lack Of Policy Permissions Access Control Acknowledged
    Location
    BPOOL.v1.sol: 254

    Description

    migrateBToken function in the BPOOL module is a permissioned function and it should be called via policies. However, none of the policies have permission to call this function.

    Recommendation

    Consider which policy is expected to call this function and add the function’s selector to the requestPermissions process.

    Resolution

    Baseline Team: Acknowledged.

  2. M-02 Medium Incorrect BPOOL Locked State Logical Error Resolved
    Location
    BPOOL.v1.sol: 75

    Description

    ERC20 features are moved from BPOOL to separate BToken contract with the current update. However, the locked status still remains in the BPOOL contract, in addition to the BToken contract, creating an asymmetry.

    The setTransferLock function correctly updates the locked status of the BToken contract, but there is no mechanism to update the locked status in BPOOL. Since BPOOL.locked is set to true in the constructor, it will always appear locked.

    This will lead to discrepancies for integrators who read BPOOL.locked instead of BPOOL.bToken.locked.

    Recommendation

    Remove the locked from the BPOOL and use it only from the BToken.

    Resolution

    Baseline Team: The issue was resolved in commit 9e4a37e.

  3. M-03 Medium Exit Loop Before Borrow Operation Logical Error Resolved
    Location
    Afterburner.sol: 254

    Description

    In the function _loop, an early exit occurs if minimumCollateral is hit. This is called after the borrow operation.

    However, if _bAssetsIn is too small, the borrow operation could revert as no new principal is transferred out. This would result in the entire reheat operation reverting.

    Recommendation

    The early exit for minimumCollateral should be done before the borrow operation.

    Resolution

    Baseline Team: The issue was resolved in commit 4e6670a.

  4. M-04 Medium probabilityDenominator Increased If No Swap Logical Error Acknowledged
    Location
    Afterburner.sol: 218

    Description

    In the reheat function, the probability denominator is incremented with each successful hit to make future hits less likely.

    However, when reserveSize = 0, no swap occurs despite the successful hit, but the probability denominator is still incremented.

    This reduces the likelihood of true hits (where actual swaps occur) since hits that result in no swaps still affect the probability, making legitimate hits less frequent.

    Recommendation

    Consider incrementing the probability denominator only if a swap occurs.

    Resolution

    Baseline Team: Acknowledged.

  5. L-01 Low Lack Of Validation In setController Warning Acknowledged
    Location
    BToken.sol

    Description

    The setController is a critical function that hands control of mint/burn ability to a new address. Given the importance of the function, consider validating the new controller address to avoid handing control to an unintended address.

    Recommendation

    Validate that _controller is not a zero address and consider implementing a two-step handover process.

    Resolution

    Baseline Team: Acknowledged.

  6. L-02 Low Remove Console2 Imports Informational Resolved
    Location
    Global

    Description

    console2 imports were found in:

    • LOOPS.v1.sol
    • BaselineInit.sol
    • LoopFacility.sol
    • MarketMaking.sol

    Recommendation

    Remove the import statements.

    Resolution

    Baseline Team: The issue was resolved in commit 9e4a37e.

  7. L-03 Low Misleading Developer Comments Informational Resolved
    Location
    MarketMaking.sol: 281, 513 - LOOPS.v1.sol: 189

    Description

    Comments on the function drop and _decrementSweepTick indicate that tick will be moved exactly one tick spacing lower. However, with the revised _getDecrementedSweepTick, it is possible to move the tick by more than one tick spacing.

    Additionally, the “transfer any surplus collateral back to the bAsset contract” comment in the LOOPS contract is incorrect, and it should be “transfer any surplus collateral back to the BPOOL contract”.

    Recommendation

    Update developer comments.

    Resolution

    Baseline Team: The issue was resolved in commit 4e6670a.

  8. L-04 Low Unexpected Behavior During High Premiums Logical Error Acknowledged
    Location
    Afterburner.sol

    Description

    When the premium between the active price and BLV is too high, no reserves are swapped during reheat due to capital inefficiency.

    However, bAssets are still converted to reserves via borrowing from the CreditFacility and defaulting on self, which burns bAsset collateral.

    Burning tokens can create upward pressure on the price, further increasing the premium, which is undesirable.

    Recommendation

    If the premium is too high, consider gracefully exiting without performing any borrowing or swapping actions.

    Resolution

    Baseline Team: Acknowledged.

More from Baseline Markets

All 12 reports
  1. Mercury, Round 3

    109 findings4 critical · 9 high 109 findings: 4 critical, 9 high, 28 medium, 33 low, 35 informational
  2. AMM, Round 2

    47 findings4 critical · 14 high 47 findings: 4 critical, 14 high, 8 medium, 13 low, 8 informational
  3. AMM

    54 findings3 critical · 6 high 54 findings: 3 critical, 6 high, 13 medium, 11 low, 21 informational
  4. Fixed Supply

    34 findings4 high 34 findings: 4 high, 10 medium, 20 low

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote