Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · April 2022

Protocol Review

for Ice Bear Society

After a line by line manual analysis and automated review, Guardian Audits has concluded that:

Published
Language
Solidity
Chains
Fantom
Sector
NFTs
  • 0 Critical
  • 0 High
  • 2 Medium
  • 3 Low
  • 0 Informational

5 resolved

Scope

Overview

After a line by line manual analysis and automated review, Guardian Audits has concluded that:

  • Ice Bear Society’s smart contracts have a LOW RISK SEVERITY
  • Ice Bear Society’s smart contracts have an ACTIVE OWNERSHIP
  • Important owner privileges – reserveForGiveaway, setSaleTime, setCost, setMaxMintAmount, setBaseURI, pause, withdraw
  • Ice Bear Society’s smart contract owner has multiple “write” privileges. Centralization risk correlated to the active ownership is MEDIUM

📜 Ice Bear Society’s contract address: 0xF33925C8F4C13ae138C8E7D159e950824990eA36

Findings 5

  1. ICE-1 Medium Centralization Risk Centralization / Privilege Resolved
    Location
    IceBearSociety.sol

    Description

    The owner address, 0xa3056090d5583747ef278f3cb6d599aa0e306e64, is not a multi-sig and has potentially dangerous permissions for renounceOwnership, transferOwnership, reserveForGiveaway, setSaleTime, setCost, setMaxMintAmount, setBaseURI, pause, withdraw, and a modified mint execution where the owner can mint Ice Bear NFTs for free.

    Recommendation

    Make the owner a multi-sig and/or introduce a timelock for improved community oversight.

  2. ICE-2 Medium Uncapped Minting Logical Error Resolved
    Location
    IceBearSociety.sol:1286

    Description

    The owner can cause the totalSupply to exceed the maxSupply by calling reserveForGiveaway with an arbitrarily large amount.

    Recommendation

    Add a require or an if statement to make sure the amount of tokens to reserve plus the current supply does not exceed the max supply.

  3. ICE-3 Low Immutability Modifiers Mutability Resolved
    Location
    IceBearSociety.sol:1268

    Description

    The devAddress, maxSupply, and baseExtension variables are never modified, and should therefore be declared constant.

    Recommendation

    Declare them as constant.

  4. ICE-4 Low Function Visibility Modifiers Optimization Resolved
    Location
    IceBearSociety.sol

    Description

    The functions mint, walletOfOwner, setCost, setMaxMintAmount, setBaseURI, pause, and withdraw are marked as public, but are never called from inside the contract.

    Recommendation

    These functions can be marked external for gas optimization and explicitness.

  5. ICE-5 Low Block Timestamp Tx Manipulation Resolved
    Location
    IceBearSociety.sol

    Description

    The mint function relies on block.timestamp which can be manipulated by validators in extreme circumstances.

    Recommendation

    The block.timestamp reliance can be safely ignored as the saleStart takes place in the past.

    While block.timestamp may be more accurate for auction time, it can be manipulated by validators. In the future, it may help to rely on block.number instead, or ensure resilience to block.timestamp manipulation.

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote