After a line by line manual analysis and automated review, Guardian Audits has concluded that:
- Published
- Language
- Solidity
- Chains
- Fantom
- Sector
- NFTs
- 0 Critical
- 0 High
- 5 Medium
- 13 Low
- 0 Informational
Scope
Overview
After a line by line manual analysis and automated review, Guardian Audits has concluded that:
- Ultimate Fantom’s smart contracts have a LOW RISK SEVERITY
- Ultimate Fantom’s smart contracts have an ACTIVE OWNERSHIP
- Important owner privileges –
setRoyaltyAddress,updateSpiritRouter,updatePaintRouter,setMintSize,sweepEthToAddress
Ultimate Fantom’s smart contract owner has multiple “write” privileges. Centralization risk correlated to the active ownership is MEDIUM
📜 Ultimate Fantom’s contract address: 0x287986A4cdfC7957e9fc273e353995BC2A2E93aE
📜 Royalty Splitter’s contract address: 0x0A5298D3ff18359d946c7BC6A1e1DF8C86aD0A96
Findings 18
-
UF-1 Medium Centralization Risk Centralization / Privilege Acknowledged
Description
The
owneraddress,0x3e522051a9b1958aa1e828ac24afba4a551df37d, is not a multi-sig and has potentially dangerous permissions forrenounceOwnership,transferOwnership,setRoyaltyAddress,setSpiritRouter,updatePaintRouter,setBaseURI,setMintSize,sweepEthToAddress.Recommendation
Make the
ownera multi-sig and/or introduce a timelock for improved community oversight.Resolution
Ultimate Fantoms: Acknowledged, contract ownership will be changed to the multisig at
0x87f385d152944689f92Ed523e9e5E9Bd58Ea62ef. -
UF-2 Medium Denial-of-Service With Failed Call DoS Acknowledged
Description
publicMintrelies on multiple external calls which can fail accidentally or deliberately. If just one consistently fails, users will not be able to mint.Recommendation
Isolate external calls to another transaction(s).
wFTMallocations could be distributed with a pull-over-push pattern.Resolution
Ultimate Fantoms: Acknowledged, failed transactions can be resubmitted + the chance of
a failed call is low.
-
UF-3 Medium Random Manipulation Tx Manipulation Acknowledged
Description
The
randomfunction relies on weak sources of pseudo-randomness from only on-chain attributes. A validator node can manipulate theblock.timestampand therefore the random number. Therefore, the_sendToaddress can be manipulated in favor of the validator.Recommendation
Utilize the Randomness pattern to obtain on-chain randomness and avoid validator manipulation or obtain random numbers off-chain through an oracle.
Resolution
Ultimate Fantoms: Acknowledged in source code.
-
UF-4 Medium Mint Failure Logical Error Resolved
Description
In
publicMint, when performing_earnTo = random() % (_tokenIdCounter.current() +1), there is a possibility_earnTois equivalent to_tokenIdCounter.current()which yields atokenIDfor a token that does not exist yet. Therefore, the subsequent call toownerOfwill fail and the mint will revert.Recommendation
Perform
random() % _tokenIdCounter.current().Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
UF-5 Medium Price Inconsistency Logical Error Resolved
Description
In the
getPricefunction the stepwise price jumps do not account for the followingtokenIds: 101, 301, 601, 1001, 1501, and 2301.This is because each
ifstatement utilizes>instead of>=when referring to these tokenIds.Therefore a mint for one of thesetokenIdswill mistakenly go to the else branch and charge 6FTM.Recommendation
Use
>=or decrement the lower boundaries by one.Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
UF-6 Low Using .transfer Best Practices Resolved
Description
transfer()comes with a fixed amount of gas.Recommendation
Utilize
call()with a success check.Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
UF-7 Low Inaccurate Comments Code Cleanliness Resolved
Description
On line 1712:
// random number between 0 to 4is inaccurate as_toEarntakes on a random value of 0 or 1.Additionally, on line 1672:
// 10%is inaccurate as_rndmAllocis calculated to be 15%.Recommendation
Refactor comments to accurately reflect the code.
Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
UF-8 Low Unnecessary Code Code Cleanliness Resolved
Description
Several functions such as
setMintFees,enableMinting,disableMinting,setTeamMinting,minterTeamMintsRemaining, andminterTeamMintsCountserve no purpose.In addition, variables such as
enableMinter,_earnAmount,_mintFees,_teamMintSize,RNDM_TOKEN,bePATH1,bePATH2,BEETS_TOKEN,bPath1,bPath2,BRUSH_TOKEN,SPIRITSWAP_TOKEN,wCYBERs,wFTMOPRs,OPR,_beetsAlloc,_treasuryAlloc,_dfyAlloc, and_teamMintCountergo unused.Recommendation
Remove unused code.
Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
UF-9 Low Repetitive Function Calls Optimization Resolved
Description
In
publicMinttherandomfunction is called several times, even though the random value is constant during each tx.Recommendation
Compute the random value once.
Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
UF-10 Low Mint Fee Manipulation Fee Manipulation Acknowledged
Description
Because the
getPricefunction is stepwise, anyone can mint 10 tokens as if they were all in a lower cost bracket while potentially only 1 was.Recommendation
Compute the mint fee for each token, account for mints that traverse the fee increase, or accept the manipulation.
Resolution
Ultimate Fantoms: Acknowledged, protocol loss will be minimal if exploited.
-
UF-11 Low Arbitrary Max Supply Tokenomics Acknowledged
Description
The
owneraddress has permissions to arbitrarilysetMintSizewhich can drastically affect the tokenomics of the project.Recommendation
Remove the
setMintSizefunction or appropriately timelock it for community trust and safety.Resolution
Ultimate Fantoms: Acknowledged, contract ownership will be changed to the multisig at
0x87f385d152944689f92Ed523e9e5E9Bd58Ea62ef. -
UF-12 Low Unequal Minting Rewards Logical Error Resolved
Description
In
publicMintthe rewards distribution toCYBERsholders can only occur on the first mint and never after.Recommendation
Ensure this is the expected behavior. If it isn’t, refactor the reward logic to more fairly include
CYBERsholders.Resolution
Ultimate Fantoms: Resolved.
-
UF-13 Low Mutability Modifiers Mutability Resolved
Description
The
_beetsAlloc,_dfyAlloc,_treasuryAlloc,mintFees, and_earnAmountvariables are never modified, and should therefore be declaredconstant.Recommendation
Declare them as
constant.Resolution
Ultimate Fantoms: Resolved, applied suggestion where appropriate.
-
UF-14 Low Function Visibility Modifiers Optimization Resolved
Description
The functions
setRoyaltyAddress,updateSpiritRouter,updatePaintRouter,publicMint,setMintFees,enableMinting,disableMinting,setBaseURI,setTeamMinting,setMintSize, andsweepEthToAddressare marked aspublic, but are never called from inside the contract.Recommendation
These functions can be marked
externalfor gas optimization.Resolution
Ultimate Fantoms: Resolved, applied suggestion where appropriate.
-
RS-1 Low Unnecessary Code Best Practices Resolved
Description
The
_earnAmountvariable goes unused.Recommendation
Remove unused code.
Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
RS-2 Low Unequal Royalty Rewards Logical Error Resolved
Description
In the
recieveandfallbackfunctions, the rewards distribution toCYBERsholders can only occur before the second mint and never after.Recommendation
Ensure this is the expected behavior. If it isn’t, refactor the reward logic to more fairly include
CYBERsholders.Resolution
Ultimate Fantoms: Resolved.
-
RS-3 Low Repetitive Function Calls Optimization Resolved
Description
In the
receiveandfallbackfunctions therandomfunction is called several times, even though the random value is constant during each tx.Recommendation
Compute the random value once.
Resolution
Ultimate Fantoms: Resolved, applied suggestion.
-
RS-4 Low Mutability Modifiers Mutability Resolved
Description
The
SPIRITSWAP_ROUTERand_earnAmountvariables are never modified, and should therefore be declaredconstant.Recommendation
Declare them as
constant.Resolution
Ultimate Fantoms: Resolved, applied suggestion where appropriate.
No findings match.
Put your code through the same review.
This review started with a conversation about scope. Tell us what you are building and we will plan yours with you.