Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · February 2025

Credit Migrator

for Baseline Markets

Baseline engaged Guardian to review the security of their Migrator Updates. From the 23rd of November to the 28th of November, a team of 2 auditors reviewed the source code in scope.

Published
Review window
November 23 to 28, 2025
Language
Solidity
Chains
Blast
Sector
Token launches
  • 0 Critical
  • 1 High
  • 0 Medium
  • 6 Low
  • 0 Informational

6 resolved · 1 acknowledged

Scope

Overview

Baseline engaged Guardian to review the security of their Migrator Updates. From the 23rd of November to the 28th of November, a team of 2 auditors reviewed the source code in scope.

Issues Detected Throughout the engagement 1 High/Critical issues were uncovered and promptly remediated by the Baseline team.

Findings 7

  1. H-01 High Sweep DoS DoS Resolved
    Location
    MarketMaking.sol

    Description

    In function drop, the liquidity added to the discovery range is liqMulWad(threshold, 1e18 + getLiquiditySpread()) while the liquidity added to the anchor range is liquidityA.

    The threshold can be smaller than the anchor’s liquidity, ultimately allowing the discovery’s liquidity to be thinner than the anchor’s liquidity.

    Because the invariant discovery liquidity ≥ anchor liquidity has been broken, function sweep can be DoS’d due to underflow when performing oldDiscovery.liquidity - liquidityA, preventing a core market making functionality from being usable.

    Recommendation

    Minimize liquidityA between the threshold and the old anchor liquidity, as done in sweep and slide.

    Resolution

    Baseline Team: The issue was resolved in commit 4d8fd4f.

  2. L-01 Low Loans Unfairly Extended By Migration Gaming Acknowledged
    Location
    CREDTMigrator.sol

    Description

    The CREDTMigrator contract allows users to migrate their loans with a discrete expiry to a LOOPS position which effectively resets their expiry in that the account will decay at the funding rate.

    Therefore a user may game this by migrating their CREDT position right before their discrete expiry is hit and enjoy the entire period that their LOOPS position loan exists.

    Recommendation

    Be aware of this potential gaming, if it is undesired consider adding a penalty for users who have already lived out a large portion of the CREDT loans.

    Resolution

    Baseline Team: Acknowledged.

  3. L-02 Low Typo Typo Resolved
    Location
    CREDTMigrator.sol: 13

    Description

    The CRETMigrator contract has a typo where the CREDT is missing the D.

    Recommendation

    Consider renaming the CRETMigrator contract to CREDTMigrator.

    Resolution

    Baseline Team: The issue was resolved in commit 4d8fd4f.

  4. L-03 Low Unnecessary Keycode Optimization Resolved
    Location
    CREDTMigrator.sol: 48

    Description

    In the requestPermissions function the BPOOL_KEYCODE is declared and unused.

    Recommendation

    Remove the BPOOL_KEYCODE variable.

    Resolution

    Baseline Team: The issue was resolved in commit 4d8fd4f.

  5. L-04 Low Missing Invariant Check Suggestion Resolved
    Location
    CREDTMigrator.sol: 57

    Description

    In the migrate function currently there is no capacity invariant check at the end of the migration to prevent a breaking of the capacity invariant.

    Currently there is no identified invalidation of this invariant due to the migration, however out of an abundance of caution it may be best to add this validation at the end of the migrate function.

    Recommendation

    Consider adding the capacity validation at the end of the migrate function.

    Resolution

    Baseline Team: The issue was resolved in commit 4d8fd4f.

  6. L-05 Low Lacking Event Emission Events Resolved
    Location
    CREDTMigrator.sol: 57

    Description

    The migrate function performs several operations of repaying and opening a new LOOPS position, however no events are emitted for this operation.

    Recommendation

    Consider emitting a migration event in the migrate function.

    Resolution

    Baseline Team: The issue was resolved in commit 4d8fd4f.

  7. L-06 Low Inconsistent Discovery Width Warning Resolved
    Location
    Global

    Description

    When launching the protocol within BaselineInit.launch the DISCOVERY_WIDTH is 350, but within the MarketMaking contract the DISCOVERY_WIDTH is 100.

    This will cause a stepwise decrease in the discovery range after a MarketMaking operation, which may be unexpected from the protocol’s perspective if the range’s size is expected to remain constant.

    Recommendation

    Document this behavior or keep the widths consistent.

    Resolution

    Baseline Team: The issue was resolved in commit e1bc337.

More from Baseline Markets

All 12 reports
  1. Mercury, Round 3

    109 findings4 critical · 9 high 109 findings: 4 critical, 9 high, 28 medium, 33 low, 35 informational
  2. AMM, Round 2

    47 findings4 critical · 14 high 47 findings: 4 critical, 14 high, 8 medium, 13 low, 8 informational
  3. AMM

    54 findings3 critical · 6 high 54 findings: 3 critical, 6 high, 13 medium, 11 low, 21 informational
  4. Fixed Supply

    34 findings4 high 34 findings: 4 high, 10 medium, 20 low

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote