Skip to content
$1,000,000 in security audit grants are live now, Apply here →

Security review · May 2022

Protocol Review

for Ultimate Fantoms

After a line by line manual analysis and automated review, Guardian Audits has concluded that:

Published
Language
Solidity
Chains
Fantom
Sector
NFTs
  • 0 Critical
  • 0 High
  • 5 Medium
  • 13 Low
  • 0 Informational

13 resolved · 5 acknowledged

Scope

Overview

After a line by line manual analysis and automated review, Guardian Audits has concluded that:

  • Ultimate Fantom’s smart contracts have a LOW RISK SEVERITY
  • Ultimate Fantom’s smart contracts have an ACTIVE OWNERSHIP
  • Important owner privileges – setRoyaltyAddress, updateSpiritRouter, updatePaintRouter, setMintSize, sweepEthToAddress

Ultimate Fantom’s smart contract owner has multiple “write” privileges. Centralization risk correlated to the active ownership is MEDIUM

📜 Ultimate Fantom’s contract address: 0x287986A4cdfC7957e9fc273e353995BC2A2E93aE

📜 Royalty Splitter’s contract address: 0x0A5298D3ff18359d946c7BC6A1e1DF8C86aD0A96

Findings 18

  1. UF-1 Medium Centralization Risk Centralization / Privilege Acknowledged
    Location
    UltimateFantoms.sol

    Description

    The owner address, 0x3e522051a9b1958aa1e828ac24afba4a551df37d, is not a multi-sig and has potentially dangerous permissions for renounceOwnership, transferOwnership, setRoyaltyAddress, setSpiritRouter, updatePaintRouter, setBaseURI, setMintSize, sweepEthToAddress.

    Recommendation

    Make the owner a multi-sig and/or introduce a timelock for improved community oversight.

    Resolution

    Ultimate Fantoms: Acknowledged, contract ownership will be changed to the multisig at

    0x87f385d152944689f92Ed523e9e5E9Bd58Ea62ef.

  2. UF-2 Medium Denial-of-Service With Failed Call DoS Acknowledged
    Location
    UltimateFantoms.sol

    Description

    publicMint relies on multiple external calls which can fail accidentally or deliberately. If just one consistently fails, users will not be able to mint.

    Recommendation

    Isolate external calls to another transaction(s). wFTM allocations could be distributed with a pull-over-push pattern.

    Resolution

    Ultimate Fantoms: Acknowledged, failed transactions can be resubmitted + the chance of

    a failed call is low.

  3. UF-3 Medium Random Manipulation Tx Manipulation Acknowledged
    Location
    UltimateFantoms.sol

    Description

    The random function relies on weak sources of pseudo-randomness from only on-chain attributes. A validator node can manipulate the block.timestamp and therefore the random number. Therefore, the _sendTo address can be manipulated in favor of the validator.

    Recommendation

    Utilize the Randomness pattern to obtain on-chain randomness and avoid validator manipulation or obtain random numbers off-chain through an oracle.

    Resolution

    Ultimate Fantoms: Acknowledged in source code.

  4. UF-4 Medium Mint Failure Logical Error Resolved
    Location
    UltimateFantoms.sol:1719

    Description

    In publicMint, when performing _earnTo = random() % (_tokenIdCounter.current() +1), there is a possibility _earnTo is equivalent to _tokenIdCounter.current() which yields a tokenID for a token that does not exist yet. Therefore, the subsequent call to ownerOf will fail and the mint will revert.

    Recommendation

    Perform random() % _tokenIdCounter.current().

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  5. UF-5 Medium Price Inconsistency Logical Error Resolved
    Location
    UltimateFantoms.sol: 1594

    Description

    In the getPrice function the stepwise price jumps do not account for the following tokenIds: 101, 301, 601, 1001, 1501, and 2301.

    This is because each if statement utilizes > instead of >= when referring to these tokenIds.Therefore a mint for one of these tokenIds will mistakenly go to the else branch and charge 6 FTM.

    Recommendation

    Use >= or decrement the lower boundaries by one.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  6. UF-6 Low Using .transfer Best Practices Resolved
    Location
    UltimateFantoms.sol:1829

    Description

    transfer() comes with a fixed amount of gas.

    Recommendation

    Utilize call() with a success check.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  7. UF-7 Low Inaccurate Comments Code Cleanliness Resolved
    Location
    UltimateFantoms.sol: 1712, 1672

    Description

    On line 1712: // random number between 0 to 4 is inaccurate as _toEarn takes on a random value of 0 or 1.

    Additionally, on line 1672: // 10% is inaccurate as _rndmAlloc is calculated to be 15%.

    Recommendation

    Refactor comments to accurately reflect the code.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  8. UF-8 Low Unnecessary Code Code Cleanliness Resolved
    Location
    UltimateFantoms.sol

    Description

    Several functions such as setMintFees, enableMinting, disableMinting, setTeamMinting, minterTeamMintsRemaining, and minterTeamMintsCount serve no purpose.

    In addition, variables such as enableMinter, _earnAmount, _mintFees, _teamMintSize, RNDM_TOKEN, bePATH1, bePATH2, BEETS_TOKEN, bPath1, bPath2, BRUSH_TOKEN, SPIRITSWAP_TOKEN, wCYBERs, wFTMOPRs, OPR, _beetsAlloc, _treasuryAlloc, _dfyAlloc, and _teamMintCounter go unused.

    Recommendation

    Remove unused code.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  9. UF-9 Low Repetitive Function Calls Optimization Resolved
    Location
    UltimateFantoms.sol

    Description

    In publicMint the random function is called several times, even though the random value is constant during each tx.

    Recommendation

    Compute the random value once.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  10. UF-10 Low Mint Fee Manipulation Fee Manipulation Acknowledged
    Location
    UltimateFantoms.sol: 1667

    Description

    Because the getPrice function is stepwise, anyone can mint 10 tokens as if they were all in a lower cost bracket while potentially only 1 was.

    Recommendation

    Compute the mint fee for each token, account for mints that traverse the fee increase, or accept the manipulation.

    Resolution

    Ultimate Fantoms: Acknowledged, protocol loss will be minimal if exploited.

  11. UF-11 Low Arbitrary Max Supply Tokenomics Acknowledged
    Location
    UltimateFantoms.sol: 1820

    Description

    The owner address has permissions to arbitrarily setMintSize which can drastically affect the tokenomics of the project.

    Recommendation

    Remove the setMintSize function or appropriately timelock it for community trust and safety.

    Resolution

    Ultimate Fantoms: Acknowledged, contract ownership will be changed to the multisig at

    0x87f385d152944689f92Ed523e9e5E9Bd58Ea62ef.

  12. UF-12 Low Unequal Minting Rewards Logical Error Resolved
    Location
    UltimateFantoms.sol: 1723

    Description

    In publicMint the rewards distribution to CYBERs holders can only occur on the first mint and never after.

    Recommendation

    Ensure this is the expected behavior. If it isn’t, refactor the reward logic to more fairly include CYBERs holders.

    Resolution

    Ultimate Fantoms: Resolved.

  13. UF-13 Low Mutability Modifiers Mutability Resolved
    Location
    UltimateFantoms.sol

    Description

    The _beetsAlloc, _dfyAlloc, _treasuryAlloc, mintFees, and _earnAmount variables are never modified, and should therefore be declared constant.

    Recommendation

    Declare them as constant.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion where appropriate.

  14. UF-14 Low Function Visibility Modifiers Optimization Resolved
    Location
    UltimateFantoms.sol

    Description

    The functions setRoyaltyAddress, updateSpiritRouter, updatePaintRouter, publicMint, setMintFees, enableMinting, disableMinting, setBaseURI, setTeamMinting, setMintSize, and sweepEthToAddress are marked as public, but are never called from inside the contract.

    Recommendation

    These functions can be marked external for gas optimization.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion where appropriate.

  15. RS-1 Low Unnecessary Code Best Practices Resolved
    Location
    RoyaltySplitter.sol

    Description

    The _earnAmount variable goes unused.

    Recommendation

    Remove unused code.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  16. RS-2 Low Unequal Royalty Rewards Logical Error Resolved
    Location
    RoyaltySplitter.sol

    Description

    In the recieve and fallback functions, the rewards distribution to CYBERs holders can only occur before the second mint and never after.

    Recommendation

    Ensure this is the expected behavior. If it isn’t, refactor the reward logic to more fairly include CYBERs holders.

    Resolution

    Ultimate Fantoms: Resolved.

  17. RS-3 Low Repetitive Function Calls Optimization Resolved
    Location
    RoyaltySplitter.sol

    Description

    In the receive and fallback functions the random function is called several times, even though the random value is constant during each tx.

    Recommendation

    Compute the random value once.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion.

  18. RS-4 Low Mutability Modifiers Mutability Resolved
    Location
    RoyaltySplitter.sol

    Description

    The SPIRITSWAP_ROUTER and _earnAmount variables are never modified, and should therefore be declared constant.

    Recommendation

    Declare them as constant.

    Resolution

    Ultimate Fantoms: Resolved, applied suggestion where appropriate.

Put your code through the same review.

This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.

Get a quote