Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[L1] Argochain | Pallets and Runtime | Oct2024

Date:

Nov 4, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the DevolvedAI team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.

ArgoChain-SDK is specifically designed for developers eager to explore and innovate within the ArgoChain ecosystem.

Document

NameBlockchain Protocol Review and Security Analysis Report for DevolvedAI
Audited ByTanuj Soni, Hamza Sajid
Approved ByNino Lipartiia
Websitehttps://devolvedai.com→
Changelog28/10/2024 - Preliminary Report
Changelog04/11/2024 - Second Preliminary Report
PlatformArgochain
LanguageRust
TagsSubstrate, EVM
Methodologyhttps://hackenio.cc/blockchain_methodology→
  • Document

    Name
    Blockchain Protocol Review and Security Analysis Report for DevolvedAI
    Audited By
    Tanuj Soni, Hamza Sajid
    Approved By
    Nino Lipartiia
    Changelog
    28/10/2024 - Preliminary Report
    Changelog
    04/11/2024 - Second Preliminary Report
    Platform
    Argochain
    Language
    Rust
    Tags
    Substrate, EVM

Review Scope

Repositoryhttps://github.com/Devolved-AI/Argochain→
Commitb35c4375d7a54adfea81a270d85c72056caaa94e

Audit Summary

9Total Findings
5Resolved
4Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • The documentation for the pallets inherited from the Frontier project → is adequate.

  • The README file would benefit from including a comprehensive system overview of the repository.

Code quality

  • The pallets exhibit strong code quality, drawing from the well-established standards of the Frontier project →.

  • Updates to both the Frontier and Substrate versions are necessary to align with recent changes.

  • Some tests and benchmarks are currently failing, suggesting the need for further improvement.

  • The presence of TODO comments in the codebase indicates areas that require additional attention.

Architecture quality

  • Leveraging the Substrate framework as the foundational infrastructure enhances the system's robustness and reliability.

  • The EVM integration is effectively achieved through the use of well-established and widely recognized pallets.

  • The runtime implementation comprehensively incorporates EVM-related pallets.

System Overview

The audit examines the integration of the EVM functionality into Argochain, covering three key pallets: pallet-ethereum, pallet-evm, and pallet-evm-chain-id, along with the associated runtime configuration.

These pallets are primarily based on the Frontier → project's implementation, with Argochain introducing only minor adjustments. The commits that introduce changes to these pallets (excluding modifications to the runtime) are outlined below.

  • Introduces the mutate_balance function, which is utilized exclusively outside the scope of the audit in pallet-counter.

  • Adds multiple functions to the EVM pallet, though these additions are not invoked elsewhere in the codebase.

  • Contains sections of code that are commented out.

  • Enhances the formatting of the evm pallet for better readability.

Following the review of the modifications applied to these pallets, it can be concluded that there have been no significant alterations since their initial adaptation from the Frontier project's implementation. The changes introduced by Argochain are largely minimal, indicating a commitment to preserving the original architectural integrity.

Risks

Scope Definition and Security Guarantees: The audit does not cover all code in the repository. Components outside the audit scope may introduce vulnerabilities, potentially impacting the overall security due to the interconnected nature of protocols.

Findings

F-2024-6651Vulnerable Dependencies and Outdated Substrate Version
Status
accepted
Severity

High
F-2024-6720Centralization Threat and Reward Imbalance Due to Era Payout Mechanism
Status
accepted
Severity

High
F-2024-6825Deficiencies in Gas Estimation Improvements
Status
fixed
Severity

Medium
F-2024-6663Incomplete EIP-3607 Implementation Allows Mempool Pollution
Status
fixed
Severity

Low
F-2024-6770Compilation Error When Enabling Runtime Benchmarks
Status
accepted
Severity

Low
F-2024-6827Inconsistent Refund Calculations
Status
fixed
Severity

Low
F-2024-6660Code Quality Warnings Highlighted in Static Analysis
Status
accepted
Severity

Observation
F-2024-6813Unit and Benchmark Test Failures
Status
fixed
Severity

Observation
F-2024-6801Unnecessary Inclusion of pallet_pov in the Runtime
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-6651Vulnerable Dependencies and Outdated Substrate Version
accepted

High
F-2024-6720Centralization Threat and Reward Imbalance Due to Era Payout Mechanism
accepted

High
F-2024-6825Deficiencies in Gas Estimation Improvements
fixed

Medium
F-2024-6663Incomplete EIP-3607 Implementation Allows Mempool Pollution
fixed

Low
F-2024-6770Compilation Error When Enabling Runtime Benchmarks
accepted

Low
F-2024-6827Inconsistent Refund Calculations
fixed

Low
F-2024-6660Code Quality Warnings Highlighted in Static Analysis
accepted

Observation
F-2024-6813Unit and Benchmark Test Failures
fixed

Observation
F-2024-6801Unnecessary Inclusion of pallet_pov in the Runtime
fixed

Observation
1-9 of 9 findings

Findings like these can secure your blockchain.

Appendix 1. Severity Definitions

Severity

Description

Critical
Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

High
High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

Medium
Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

Low
Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
  • Severity

    Critical

    Description

    Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

    Severity

    High

    Description

    High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

    Severity

    Medium

    Description

    Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

    Severity

    Low

    Description

    Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.

Appendix 2. Scope

The scope of the project includes the following components from the provided repository:

Scope Details

Repositoryhttps://github.com/Devolved-AI/Argochain→
Commitb35c4375d7a54adfea81a270d85c72056caaa94e

Components in Scope

The audit covers the implementation of three specific pallets, as well as the associated runtime configuration. The components under review are:

  • frame/ethereum

  • frame/evm-chain-id

  • frame/evm

  • runtime

Assets in Scope

Code Quality - Code Quality
Dependencies - Dependencies
ethereum - ethereum
evm - evm
frame
ethereum
src
lib.rs - frame › ethereum › src › lib.rs
evm
src
lib.rs - frame › evm › src › lib.rs
evm-chain-id
src
lib.rs - frame › evm-chain-id › src › lib.rs
Runtime - Runtime
runtime
src
lib.rs file - runtime › src › lib.rs file

Disclaimer