Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · April 2022

Protocol Review

for Hamsters of Opera

After a line by line manual analysis and automated review, Guardian Audits has concluded that:

Published
Language
Solidity
Chains
Fantom
Sector
Tokens
  • 0 Critical
  • 0 High
  • 3 Medium
  • 14 Low
  • 0 Informational

17 resolved

Scope

Overview

After a line by line manual analysis and automated review, Guardian Audits has concluded that:

  • Hamsters of Opera’s smart contracts have a MEDIUM RISK SEVERITY
  • Hamsters of Opera’s smart contracts have an ACTIVE OWNERSHIP
  • Important operator privileges – setTaxOffice, setTaxRate, setLockUp, setOperator, allocateSeignorage, hamsterWheelSetLockUp, setBondDepletionFloorPercent, setBootstrap, setDiscountPercent, setExtraFunds, setHamsterOracle, setHamsterPriceCeiling, setHamsterWheel, setMaxDebtRatioPercent, setMaxExpansionTiersEntry, setMaxPremiumRate, setMaxSupplyContractionPercent, setMaxSupplyExpansionPercents, setMintingFactorForPayingDebt, setPremiumPercent, setPremiumThreshold, setSupplyTiersEntry.
  • Hamsters of Opera’s smart contract owner has multiple “write” privileges. Centralization risk correlated to the active ownership is HIGH

Findings 17

  1. HAM-1 Medium Uncapped Tax Centralization / Privilege Resolved
    Location
    Hamster.sol:159

    Description

    The setTaxRate function allows for a tax as high as 99.99% to be imposed, which can lead to near total loss of funds for users.

    Recommendation

    Require a more strict cap on the taxRate and/or timelock the setTaxRate function.

  2. HAM-2 Low Unchecked Return Value Control Flow Resolved
    Location
    Hamster.sol:122

    Description

    The governanceRecoverUnsupported function uses transfer which provides a return value that should be checked. Not all ERC20 implementations revert in case of failure, so it is important to have some logic in the event these executions fail.

    Recommendation

    Check the return value, or opt for a safeTransfer alternative.

  3. SHARE-1 Low Block Timestamp Tx Manipulation Resolved
    Location
    HShare.sol: 25, 32, 68, 73

    Description

    Possibly dangerous reliance on block.timestamp. block.timestamp can be manipulated by validators.

    Recommendation

    Rely on block.number instead, or ensure resilience to block.timestamp manipulation.

  4. SHARE-2 Low Immutability Modifiers Mutability Resolved
    Location
    HShare.sol

    Description

    The communityFundAllocation, devFundAllocation, vestingDuration, startTime, endTime, communityFundRewardRate, and devFundRewardRate variables are only set in the constructor, and should therefore be declared immutable.

    Recommendation

    Declare them as immutable.

  5. REWARD-1 Low Block Timestamp Tx Manipulation Resolved
    Location
    HamsterRewardPool.sol: 39, 40, 95, 123, 132, 133, 136, 184, 236, 241, 249, 253

    Description

    Possibly dangerous reliance on block.timestamp. block.timestamp can be manipulated by validators.

    Recommendation

    Rely on block.number instead, or ensure resilience to block.timestamp manipulation.

  6. REWARD-2 Low Memory Usage Optimization Resolved
    Location
    HamsterRewardPool.sol: 35, 151, 170, 188, 210

    Description

    The pool variable is often declared storage when it is not modified.

    Recommendation

    Declare it as memory to save on gas.

  7. REWARD-3 Low Immutability Modifiers Mutability Resolved
    Location
    HamsterRewardPool.sol

    Description

    The hamster and poolStartTime variables are only set in the constructor, and should therefore be declared immutable.

    Recommendation

    Declare them as immutable.

  8. REWARD-4 Low poolInfo Denial of Service Denial of Service Resolved
    Location
    HamsterRewardPool.sol

    Description

    The operator can use add to extend the poolInfo list. If poolInfo becomes significantly long it can cause high gas consumption for the governanceRecoverUnsupported, massUpdatePools, checkPoolDuplicate, add, and set functions.

    If the gas consumption were to exceed the transaction limit as a result, these functions would be rendered useless.

    Recommendation

    Timelock the add function or limit the maximum size of poolInfo.

  9. WHEEL-1 Low Arbitrary Lockup Centralization / Privilege Resolved
    Location
    HamsterWheel.sol: 124

    Description

    Using setLockup, the operator can arbitrarily set the withdrawLockupEpochs and rewardLockupEpochs as high as 56 epochs retroactively after an address has locked.

    Recommendation

    Timelock the setLockup sufficiently such that all current locks can become unlocked before the new lockup is applied, or refactor the logic such that the new lockup only applies to new lockers.

  10. WHEEL-2 Low Missing Events Events Resolved
    Location
    HamsterWheel.sol

    Description

    The setOperator and setLockup functions change state that affects stakeholders so they should emit corresponding events.

    Recommendation

    Add event emissions to setOperator and setLockup.

  11. TRS-1 Low Immutability Modifiers Mutability Resolved
    Location
    Treasury.sol

    Description

    The hamster and poolStartTime variables are only set in the constructor, and should therefore be declared immutable.

    Recommendation

    Declare them as immutable.

  12. TRS-2 Medium Centralization Risk Centralization / Privilege Resolved
    Location
    Treasury.sol

    Description

    The operator address is not a multi-sig and has potentially dangerous permissions for hamsterWheelSetOperator, hamsterWheelAllocateSeigniorage, hamsterWheelSetLockUp, setBondDepletionFloorPercent, setBootstrap, setDiscountPercent, setExtraFunds, setHamsterOracle, setHamsterPriceCeiling, setHamsterWheel, setMaxDebtRatioPercent, setMaxExpansionTiersEntry, setMaxPremiumRate, setMaxSupplyContractionPercent, setMaxSupplyExpansionPercents, setMintingFactorForPayingDebt, setPremiumPercent, setPremiumThreshold, setSupplyTiersEntry

    Recommendation

    Make the operator a multi-sig and/or introduce a timelock for the community to monitor events.

  13. TAX-1 Low Immutability Modifiers Mutability Resolved
    Location
    TaxOfficeV2.sol: 124

    Description

    The hamster and router variables are only set in the constructor, and should therefore be declared immutable for gas optimization.

    Recommendation

    Declare them as immutable.

  14. TAX-2 Low Tax Inclusion Manipulation Centralization / Privilege Resolved
    Location
    TaxOfficeV2.sol

    Description

    If setTaxExclusionForAddress was called by the operator and set to true for an address, that address can call taxFreeTransferFrom with an excluded sender. Afterwards, the sender would be included in the tax.

    Recommendation

    Introduce a timelock such that the community can monitor what the operator sets.

  15. TAX-3 Low Unchecked Return Value Control Flow Resolved
    Location
    TaxOfficeV2.sol: 84, 102

    Description

    The addLiquidityTaxFree function uses transfer which provides a return value that should be checked. Not all ERC20 implementations revert in case of failure, it is important to have some logic in the event these executions fail.

    Recommendation

    Check the return value, or opt for a safeTransfer alternative.

  16. TAX-4 Medium Centralization Risk Centralization / Privilege Resolved
    Location
    TaxOfficeV2.sol

    Description

    The operator address is not a multi-sig and has potentially dangerous permissions for disableAutoCalculateTax, enableAutoCalculateTax, excludeAddressFromTax, includeAddressInTax, setBurnThreshold, setTaxCollectorAddress, setTaxExclusionForAddress, setTaxRate, setTaxTiersRate, setTaxTiersTwap, setTaxableHamsterOracle, transferTaxOffice

    Most notably transferTaxOffice sets the taxOffice for the hamster contract, potentially compromising the hamster taxOffice permissioned functions as well.

    Recommendation

    Make the operator a multi-sig and/or introduce a timelock for the community to monitor events.

  17. TAX-5 Low Missing Events Events Resolved
    Location
    TaxOfficeV2.sol

    Description

    The disableAutoCalculateTax, enableAutoCalculateTax, excludeAddressFromTax, includeAddressInTax, setBurnThreshold, setTaxCollectorAddress, setTaxExclusionForAddress, setTaxRate, setTaxTiersRate, setTaxTiersTwap, setTaxableHamsterOracle, transferTaxOffice functions change state that affects stakeholders so they should emit corresponding events.

    Recommendation

    Add event emissions to these functions.

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote