Synthetix engaged Guardian to review the security of its review of their TLX to SNX token conversion contract. From the 19th of December to the 23rd of December, a team of 2 auditors reviewed the source code in scope.
- Published
- Review window
- December 19 to 23, 2024
- Language
- Solidity
- Chains
- Optimism
- Sector
- Tokens
- 0 Critical
- 0 High
- 0 Medium
- 5 Low
- 0 Informational
Scope
Overview
Synthetix engaged Guardian to review the security of its review of their TLX to SNX token conversion contract. From the 19th of December to the 23rd of December, a team of 2 auditors reviewed the source code in scope.
Findings 5
-
L-01 Low Unexpected Lock End Date Unexpected Behavior Resolved
Description
In the constructor for the
TLXConversioncontract thetimeLockEndsis assigned to theVESTING_START_TIME+ 30 days.It was mentioned that the lock end date is expected to be January 5th, but since December has 31 days the lock end date is instead January 4th.
vesting start time: 1733356800 30 days: 2592000 end timestamp: 1735948800 (Jan. 4th 12 AM GMT)
Recommendation
Consider if this is the expected lock end date, if it is then no changes are necessary. If the lock end date must be January 5th then update the
VESTING_LOCK_DURATIONto 31 days.Resolution
Synthetix Team: The issue was resolved in commit 25c65e7.
-
L-02 Low timeLockEnds Optimization Optimization Resolved
Description
In the
vestableAmountfunction there is an early return case forblock.timestamp < timeLockEnds, however if theblock.timestampis equal to thetimeLockEndstime then the early return of 0 vested amount can apply as well.Recommendation
Consider updating the early return case to include
block.timestamp <= timeLockEnds.Resolution
Synthetix Team: The issue was resolved in commit 7cf2092.
-
L-03 Low No Requirement To Lock For The Lock Period Unexpected Behavior Acknowledged
Description
In the
TLXConversioncontract there is no requirement that userslockAndConverttheir funds and wait for the full locking period of 30 days. A user may lock their TLX the day before the lock period ends and only have to lock their funds for a single day.Recommendation
It is unclear if this is the expected behavior. If it is not, consider tracking locked period per account and require all accounts to wait for a 30 day lock period.
Resolution
Synthetix Team: finding is intended behavior.
-
L-04 Low Lacking Event Emission Events Resolved
Description
In the
withdrawSNXthere is no event emitted to indicate that the SNX treasury has withdrawn the remaining SNX tokens from the vester contract.Recommendation
Consider adding an event emission to indicate that the remaining SNX tokens have been withdrawn.
Resolution
Synthetix Team: The issue was resolved in commit 8d37f14.
-
L-05 Low Additional SNX Trapped For 2 Years Warning Acknowledged
Description
In the
TlxConversioncontract the SNX balance of the contract may not be withdrawn for 2 years after the unlock date. This includes any SNX tokens that may have been accidentally sent to theTlxConversioncontract in excess of the amount which should be vested.Recommendation
Consider determining the exact amount of SNX required for the TLX vest and allowing any additional SNX balance in excess of the total SNX required minus the amount claimed thus far to be re-claimed by the SNX treasury at any time.
Resolution
Synthetix Team: Acknowledged.
No findings match.
More from Synthetix
All 14 reports-
Update Reviews
34 findings2 critical · 4 high 34 findings: 2 critical, 4 high, 13 medium, 10 low, 5 informational -
Deposit Contract
38 findings1 high 38 findings: 1 high, 6 medium, 20 low, 11 informational -
Fixed Staking Rewards
6 findings1 high 6 findings: 1 high, 2 medium, 3 low -
Auto-Compounding LP Vault
80 findings1 critical · 4 high 80 findings: 1 critical, 4 high, 14 medium, 61 low
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.
