After a line by line manual analysis and automated review, Guardian Audits has concluded that:
- Published
- Language
- Solidity
- Chains
- Fantom
- Sector
- Tokens
- 0 Critical
- 0 High
- 3 Medium
- 14 Low
- 0 Informational
Scope
Overview
After a line by line manual analysis and automated review, Guardian Audits has concluded that:
- Hamsters of Opera’s smart contracts have a MEDIUM RISK SEVERITY
- Hamsters of Opera’s smart contracts have an ACTIVE OWNERSHIP
- Important operator privileges –
setTaxOffice,setTaxRate,setLockUp,setOperator,allocateSeignorage,hamsterWheelSetLockUp,setBondDepletionFloorPercent,setBootstrap,setDiscountPercent,setExtraFunds,setHamsterOracle,setHamsterPriceCeiling,setHamsterWheel,setMaxDebtRatioPercent,setMaxExpansionTiersEntry,setMaxPremiumRate,setMaxSupplyContractionPercent,setMaxSupplyExpansionPercents,setMintingFactorForPayingDebt,setPremiumPercent,setPremiumThreshold,setSupplyTiersEntry. - Hamsters of Opera’s smart contract owner has multiple “write” privileges. Centralization risk correlated to the active ownership is HIGH
Findings 17
-
HAM-1 Medium Uncapped Tax Centralization / Privilege Resolved
Description
The
setTaxRatefunction allows for a tax as high as 99.99% to be imposed, which can lead to near total loss of funds for users.Recommendation
Require a more strict cap on the
taxRateand/or timelock thesetTaxRatefunction. -
HAM-2 Low Unchecked Return Value Control Flow Resolved
Description
The
governanceRecoverUnsupportedfunction usestransferwhich provides a return value that should be checked. Not all ERC20 implementations revert in case of failure, so it is important to have some logic in the event these executions fail.Recommendation
Check the return value, or opt for a
safeTransferalternative. -
REWARD-1 Low Block Timestamp Tx Manipulation Resolved
Description
Possibly dangerous reliance on
block.timestamp.block.timestampcan be manipulated by validators.Recommendation
Rely on
block.numberinstead, or ensure resilience toblock.timestampmanipulation. -
REWARD-2 Low Memory Usage Optimization Resolved
Description
The
poolvariable is often declaredstoragewhen it is not modified.Recommendation
Declare it as
memoryto save on gas. -
REWARD-3 Low Immutability Modifiers Mutability Resolved
Description
The
hamsterandpoolStartTimevariables are only set in the constructor, and should therefore be declaredimmutable.Recommendation
Declare them as
immutable. -
REWARD-4 Low poolInfo Denial of Service Denial of Service Resolved
Description
The
operatorcan useaddto extend thepoolInfolist. IfpoolInfobecomes significantly long it can cause high gas consumption for thegovernanceRecoverUnsupported,massUpdatePools,checkPoolDuplicate,add, andsetfunctions.If the gas consumption were to exceed the transaction limit as a result, these functions would be rendered useless.
Recommendation
Timelock the
addfunction or limit the maximum size ofpoolInfo. -
WHEEL-1 Low Arbitrary Lockup Centralization / Privilege Resolved
Description
Using
setLockup,theoperatorcan arbitrarily set thewithdrawLockupEpochsandrewardLockupEpochsas high as 56 epochs retroactively after an address has locked.Recommendation
Timelock the
setLockupsufficiently such that all current locks can become unlocked before the new lockup is applied, or refactor the logic such that the new lockup only applies to new lockers. -
WHEEL-2 Low Missing Events Events Resolved
Description
The
setOperatorandsetLockupfunctions change state that affects stakeholders so they should emit corresponding events.Recommendation
Add event emissions to
setOperatorandsetLockup. -
TRS-1 Low Immutability Modifiers Mutability Resolved
Description
The
hamsterandpoolStartTimevariables are only set in the constructor, and should therefore be declaredimmutable.Recommendation
Declare them as
immutable. -
TRS-2 Medium Centralization Risk Centralization / Privilege Resolved
Description
The
operatoraddress is not a multi-sig and has potentially dangerous permissions forhamsterWheelSetOperator,hamsterWheelAllocateSeigniorage,hamsterWheelSetLockUp,setBondDepletionFloorPercent,setBootstrap,setDiscountPercent,setExtraFunds,setHamsterOracle,setHamsterPriceCeiling,setHamsterWheel,setMaxDebtRatioPercent,setMaxExpansionTiersEntry,setMaxPremiumRate,setMaxSupplyContractionPercent,setMaxSupplyExpansionPercents,setMintingFactorForPayingDebt,setPremiumPercent,setPremiumThreshold,setSupplyTiersEntryRecommendation
Make the
operatora multi-sig and/or introduce a timelock for the community to monitor events. -
TAX-1 Low Immutability Modifiers Mutability Resolved
Description
The
hamsterandroutervariables are only set in the constructor, and should therefore be declaredimmutablefor gas optimization.Recommendation
Declare them as
immutable. -
TAX-2 Low Tax Inclusion Manipulation Centralization / Privilege Resolved
Description
If
setTaxExclusionForAddresswas called by theoperatorand set to true for an address, that address can calltaxFreeTransferFromwith an excluded sender. Afterwards, the sender would be included in the tax.Recommendation
Introduce a timelock such that the community can monitor what the
operatorsets. -
TAX-3 Low Unchecked Return Value Control Flow Resolved
Description
The
addLiquidityTaxFreefunction usestransferwhich provides a return value that should be checked. Not all ERC20 implementations revert in case of failure, it is important to have some logic in the event these executions fail.Recommendation
Check the return value, or opt for a
safeTransferalternative. -
TAX-4 Medium Centralization Risk Centralization / Privilege Resolved
Description
The
operatoraddress is not a multi-sig and has potentially dangerous permissions fordisableAutoCalculateTax,enableAutoCalculateTax,excludeAddressFromTax,includeAddressInTax,setBurnThreshold,setTaxCollectorAddress,setTaxExclusionForAddress,setTaxRate,setTaxTiersRate,setTaxTiersTwap,setTaxableHamsterOracle,transferTaxOfficeMost notably
transferTaxOfficesets thetaxOfficefor thehamstercontract, potentially compromising thehamster taxOfficepermissioned functions as well.Recommendation
Make the
operatora multi-sig and/or introduce a timelock for the community to monitor events. -
TAX-5 Low Missing Events Events Resolved
Description
The
disableAutoCalculateTax,enableAutoCalculateTax,excludeAddressFromTax,includeAddressInTax,setBurnThreshold,setTaxCollectorAddress,setTaxExclusionForAddress,setTaxRate,setTaxTiersRate,setTaxTiersTwap,setTaxableHamsterOracle,transferTaxOfficefunctions change state that affects stakeholders so they should emit corresponding events.Recommendation
Add event emissions to these functions.
No findings match.
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.