After a line by line manual analysis and automated review, Guardian has concluded that:
- Published
- Language
- Solidity
- Chains
- BNB Chain
- Sector
- Tokens
- 0 Critical
- 0 High
- 1 Medium
- 11 Low
- 0 Informational
Scope
Overview
After a line by line manual analysis and automated review, Guardian has concluded that:
- Infinity Lotto’s smart contracts have a LOW RISK SEVERITY
- Infinity Lotto’s smart contracts have an ACTIVE OWNERSHIP
- Important owner privileges –
authorize,unauthorize,transferOwnership,addStakingContract,removeBadStakingContract,setAutomatedMarketMakerPair,updateClaimWait,setMaxWalletPercent_base1000,tradingStatus, cooldownEnabled,enable_blacklist,manage_blacklist,setSellMultiplier,multiAirdrop,multiAirdrop_fixed,addTeamDivWallet,removeTeamDivWallet,setIsFeeExempt,setGoldenModeTaxByIs0,setIsTimelockExempt,setIsTxLimitExempt,setIsMaxWalletExempt,setContractFees,setFeeContract,setSwapBackSettings,setDistributorSettings,withdrawlToken,updateRouter - Infinity Lotto’s smart contract owner has multiple “write” privileges. Centralization risk correlated to the active ownership is MEDIUM
Findings 12
-
LOT-1 Medium Centralization Risk Centralization / Privilege Resolved
Description
Privileged addresses have authority over many functions that may be used to negatively disrupt the project. Some important privileges include:
ownercan blacklist an address preventing it from swapping ILOTTO tokens. Additionally, the token pair or exchange router could be blacklisted, which would cease trading.ownercan setisMaxWalletExemptto false for the pair contract, thus halting all trading.ownercan label an address ateamDivWalletwhich would instantaneously create more XiLotto dividend tokens and would dilute the future dividends of other holders. Furthermore, this allows the team to to dump on the market without any cooldown.ownercan toggletradingStatustofalsewhich would prevent users from transferring funds and cease trading on all exchanges.ownercanupdateClaimWaitto an arbitrarily long period, potentially preventing XiLotto holders from ever claiming their dividends.- Any
authorizedaddress can update therouterto a potentially malicious contract that causes a denial-of-service via reverting, or siphons funds upon execution of swapBack rather than distributing these funds as dividends. ownercan set thecooldownTimerIntervalto an arbitrarily long length of time, making it so that addresses are potentially only able to buy ILotto2 once. Additionally,ownercan combine an extremely longcooldownTimerIntervalwith adding the exchange’s router as anautomatedMarketMakerPair, this way any address can potentially only buy/sell one time.
Recommendation
Currently the
owneraddress is not a multi-sig. Ensure that the privileged addresses are multi-sig and/or introduce timelock for improved community oversight. Optionally introducerequirestatements to limit the scope of the exploits that can be carried out by the privileged addresses.Resolution
Infinity Lotto Team: **
- Contract Ownership is transferred a multi sig wallet
-
LOT-2 Low Multiplication On Result Of Division Precision Acknowledged
Description
In the function
takeFee:uint256 feeAmount = amount.div(feeDenominator *100).mul(totalFee).mul(multiplier)performs multiplication on the result of division, which leads to a loss in precision.For example: 100.div(100 * 100).mul(10).mul(100) = 0 but 100.mul(10).mul(100).div(100 * 100) = 10
Recommendation
Change to
uint256 feeAmount = (amount * totalFee * multiplier) / (feeDenominator * 100).Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-3 Low Constant Modifiers Mutability Acknowledged
Description
Contract variables such as
MAX_INT,RWRD,DEAD,ZERO,_totalSupply,feeDenominatorcan be declaredconstant.Recommendation
Declare the variables
constant.Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-4 Low Immutable Modifiers Mutability Acknowledged
Description
The
WBNBanddistributorvariables are never modified after they are set in the constructor, and should therefore be declaredimmutable.Recommendation
Declare the variables
immutable.Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-5 Low SafeMath Operations Best Practices Acknowledged
Description
There is no need for
add,sub,mul, anddivin Solidity version^0.8.0as there are already implicit overflow and underflow checks.Recommendation
Use language provided operators
+,-,*,/to save on gas.Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-6 Low Superfluous Mapping Optimization Acknowledged
Description
In the XiLotto contract, the
tokenHoldersMapis declared as anIterableMapping, but it is only ever used to access the values of the keys. Therefore the use ofIterableMappingis gas inefficient and it can be replaced as a list.Recommendation
Replace the
tokenHoldersMapwith a list of tokenHolders.Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-7 Low Internal Functions Best Practices Acknowledged
Description
Internal functions should be denoted with a preceding
_:checkTxLimit,shouldTakeFee,takeFee,shouldSwapBack,swapBack,swapAndSendToDiv.Recommendation
Rename these functions to
_checkTxLimit,_shouldTakeFee,_takeFee,_shouldSwapBack,_swapBack,_swapAndSendToDiv.Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-8 Low External Modifiers Best Practices Acknowledged
Description
Many
publicfunctions can be declaredexternal:tradingStatus,cooldownEnabled,enable_blacklist,manage_blacklist,getCirculatingSupply,addTeamDivWallet,setAutomatedMarketMakerPair.Recommendation
Declare these functions
externalas they are never called internally.Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-9 Low Lack of CamelCase Best Practices Acknowledged
Description
Function names should adhere to camelCase:
enable_blacklist,manage_blacklist.Recommendation
Introduce camelCase instead of snake_case.
Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-10 Low Typo Typos Acknowledged
Description
withdrawlTokenshould bewithdrawalToken.Recommendation
Fix spelling for cleaner code.
Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-11 Low Residual MaxWalletExemption Logical Error Acknowledged
Description
When
removeBadStakingContractis called,isMaxWalletExemptis not reset tofalse.Recommendation
If this is not intended, perform
isMaxWalletExempt[badStakingContract] = false;ordeleteisMaxWalletExempt[badStakingContract].Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
-
LOT-12 Low Boolean Redundancy Optimization Acknowledged
Description
In
updateRouterthe finalifstatement condition isautomatedMarketMakerPairs[pair] != true, but this is redundant since the mapping values are booleans themselves.Recommendation
Replace the
ifstatement condition with a more gas efficient!automatedMarketMakerPairs[pair].Resolution
Infinity Lotto Team: **
- Acknowledged, but not changed as this doesn’t significantly affect the token and would require a contract migration.
No findings match.
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.