Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] 1DFX | Staking Pool | Jul2024

Date:

Aug 6, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the 1DFX team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

The staking product, 1DFX, aims to attract crypto-native traders, liquidity providers, and novice crypto traders by offering incentives for early participation. It establishes a liquidity pool where participants can deposit tokens, receive LP tokens, and stake them to earn 1DFX tokens as rewards.

Document

NameSmart Contract Code Review and Security Analysis Report for 1DFX
Audited ByTurgay Arda Usman
Approved ByAtaberk Yavuzer
WebsiteN/A
Changelog19/07/2024 - Preliminary Report
06/08/2024 - Final Report
LanguageSolidity
TagsStaking
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for 1DFX
    Audited By
    Turgay Arda Usman
    Approved By
    Ataberk Yavuzer
    Website
    N/A
    Changelog
    19/07/2024 - Preliminary Report
    06/08/2024 - Final Report
    Language
    Solidity
    Tags
    Staking

Review Scope

Repositoryhttps://git.liquid-lab.io/1dfx/1dfx-staking-pool→
Commite978e43bebb02e1a221be571c3b304ae0bd2b359

Audit Summary

7Total Findings
2Resolved
2Accepted
3Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Functional requirements are provided.

  • Technical description is partially provided.

Code quality

  • The code  mostly follows best practices and style guides.

    • See informational issues and observations for more details.

  • The development environment is configured.

Test coverage

Code coverage of the project is 100% (branch coverage),

  • Deployment and basic user interactions are covered with tests.

  • Negative cases coverage is covered with tests.

  • Interactions by several users are tested thoroughly.

System Overview

The staking product, 1DFX, aims to attract crypto-native traders, liquidity providers, and novice crypto traders by offering incentives for early participation. It establishes a liquidity pool where participants can deposit tokens, receive LP tokens, and stake them to earn 1DFX tokens as rewards. The product focuses on providing a fair reward distribution, preventing price discovery initially, and incentivizing liquidity providers to keep their funds in the pool through staking rewards and vesting mechanisms. It has the following contracts:

StakingTokenFacet — Facet for staking, unstaking, and claiming rewards. LibRewardPool — Library for managing the reward pool, including initialization and reward parameter management. RewardPoolFacet — Facet for managing reward parameters and calculations. LibStakingToken — Library for managing staking token operations including staking, unstaking, and reward calculations. LeadInPoolFacet —Facet for handling immature staking records. LibLeadInPool — Library for managing the immature staking records.

Privileged roles

  • STAKE_POOL_MANAGER can set reward and staking parameters.

  • STAKE_POOL_MANAGER can lock reward pool parameters.

Risks

The audit does not cover all code in the repository. Contracts outside the audit scope may introduce vulnerabilities, potentially impacting the overall security due to the interconnected nature of smart contracts.

The implemented LibLeadInPool, RewardPoolFacet, LibStakingToken, StakingTokenFacet, IRewardMintableToken logics highly depend on external contracts not covered by the audit. This reliance introduces risks if these external contracts are compromised or contain vulnerabilities, affecting the audited project's integrity.

The project iterates over large dynamic arrays, which leads to excessive gas costs, risking denial of service due to out-of-gas errors, directly impacting contract usability and reliability.

The current version of the code does not support fee-on-transfer tokens. Adding such tokens in the future can create risks.

Findings

F-2024-4325Inefficient Deletion Logic
Status
accepted
Severity

Low
F-2024-4328Unsafe Downcasting to Uint40
Status
accepted
Severity

Observation
F-2024-4326Division Before Multiplication
Status
mitigated
Severity

Observation
F-2024-4324Comparison of Different Uint Types
Status
mitigated
Severity

Observation
F-2024-4323Division by Zero
Status
fixed
Severity

Observation
F-2024-4322Overflow Possibility in Mathematical Operations
Status
mitigated
Severity

Observation
F-2024-6353Reinserting After All Dequeues Leads to Queue Growing Indefinitely
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-4325Inefficient Deletion Logic
accepted

Low
F-2024-4328Unsafe Downcasting to Uint40
accepted

Observation
F-2024-4326Division Before Multiplication
mitigated

Observation
F-2024-4324Comparison of Different Uint Types
mitigated

Observation
F-2024-4323Division by Zero
fixed

Observation
F-2024-4322Overflow Possibility in Mathematical Operations
mitigated

Observation
F-2024-6353Reinserting After All Dequeues Leads to Queue Growing Indefinitely
fixed

Observation
1-7 of 7 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Severity Definitions

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Scope Details

Repositoryhttps://git.liquid-lab.io/1dfx/1dfx-staking-pool→
Commite978e43bebb02e1a221be571c3b304ae0bd2b359
Whitepaperprovided as a file
Requirementsprovided as a file
Technical Requirementsprovided as a file

Contracts in Scope

RewardPoolFacet.sol - RewardPoolFacet.sol
Constants.sol - Constants.sol
LeadInPoolFacet.sol - LeadInPoolFacet.sol
ILeadInPool.sol - ILeadInPool.sol
IRewardPool.sol - IRewardPool.sol
StakingTokenFacet.sol - StakingTokenFacet.sol
IStakingToken.sol - IStakingToken.sol
IRewardMintableToken.sol - IRewardMintableToken.sol
IStakingCustomError.sol - IStakingCustomError.sol
LibRewardPool.sol - LibRewardPool.sol
LibLeadInPool.sol - LibLeadInPool.sol
LibStakingToken.sol - LibStakingToken.sol

Disclaimer