Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] Dropnest | Protocol-Contracts | June2024

Date:

Jul 11, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Dropnest team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

The DropnestStaking protocol is a smart contract system for EVM chains. It is designed to manage deposits for the Dropnest protocol and record the deposits via emitting events into the blockchain. Deposited tokens are then sent to external protocols for farming.

Document

NameSmart Contract Code Review and Security Analysis Report for Dropnest
Audited ByDavid Camps Novi, Viktor Lavrenenko
Approved ByPrzemyslaw Swiatowiec
Websitehttps://www.dropnest.xyz/→
Changelog27/06/2024 - Preliminary Report; 04/07/2024 - Final Report
PlatformEthereum, Base, Optimism, Arbitrum, Linea, Blast, Polygon
LanguageSolidity
TagsStaking, Farming
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for Dropnest
    Audited By
    David Camps Novi, Viktor Lavrenenko
    Approved By
    Przemyslaw Swiatowiec
    Changelog
    27/06/2024 - Preliminary Report; 04/07/2024 - Final Report
    Platform
    Ethereum, Base, Optimism, Arbitrum, Linea, Blast, Polygon
    Language
    Solidity
    Tags
    Staking, Farming

Review Scope

Repositoryhttps://github.com/Nest-Layer/dropnest-protocol-contracts/→
Commit60be644381df46440497434ab1900258b17e05fc

Audit Summary

7Total Findings
6Resolved
0Accepted
1Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Functional requirements are limited.

    • Basic system description is provided.

    • System roles are explained.

  • Technical description is complete.

    • NatSpec is provided.

    • Run instructions are present.

Code quality

  • The development environment is configured.

  • Inefficient gas model: F-2024-4045, F-2024-4050.

  • Best practices are followed.

Test coverage

Code coverage of the project is 94.4% (branch coverage).

  • Deployment and basic user interactions are covered with tests.

  • Negative cases coverage is extensively tested.

System Overview

The DropnestStaking protocol is a smart contract system for EVM chains. It is designed to manage deposits for the Dropnest protocol and record the deposits via emitting events into the blockchain. Deposited tokens are then sent to external protocols for farming.

  • Staking: Users can stake their ETH or predetermined ERC20 tokens on a specific protocol. The staked tokens are transferred to the farmer address of the protocol.

  • Multiple Staking: Users can also stake their ETH or ERC20 tokens on multiple protocols at once. The total amount of tokens staked should be equal to the sum of the individual amounts staked on each protocol.

Privileged roles

  • The owner of the contract can

    • Add new protocols or update the farmer address for existing ones.

    • Pause and unpause the contract.

    • Set the status of a protocol from active to inactive, and vice-versa.

Risks

The audited contract DropnestStaking is highly centralized, introducing single points of failure and control. This centralization can lead to vulnerabilities in decision-making and operational processes, making the system more susceptible to targeted attacks or manipulation. The centralization is expressed by the reliance on the protocol owners for:

Tracking deposits from users into the protocol, and subsequent calculation and management of staking rewards and users' funds, off-chain.

Managing interactions with the farming protocols used by the system, off-chain.

Pausing and unpausing the contract.

Adding and removing supported tokens.

Managing the farming protocols' statuses and addresses.

The digital contract architecture relies on administrative keys for critical operations. Centralized control over these keys presents a significant security risk, as compromise or misuse can lead to unauthorized actions or loss of funds. Such operations are:

Pause and unpause the contract.

Add and remove supported tokens.

Manage the farming protocols' statuses and addresses.

The implemented farmAddresses and supportedTokens logic highly depends on external contracts not covered by the audit. This reliance introduces risks if these external contracts are compromised or contain vulnerabilities, affecting the audited project's integrity. More details about such contracts and their usage can be found in the project README.

The DropnestStaking contract contains the staking functionality of the system, through which users' deposits are tracked using the events Deposited and ERC20Deposited. The amounts are tracked off-chain, where additional calculations take place in order to complete the staking functionality (balance tracking, rewards, etc.).

Although the team does not currently plan to support fee-on-transfer tokens, if such kind of tokens (or any other kind of token were the input amount and received amount could be different) were introduced in the system, the off-chain part of the protocol should be adapted. Otherwise, there could be mismatches between the tracked amount emitted by the events and the actual transferred amount, resulting in wrong calculations and balance tracking in the system. The project README provides further insights on this topic, where the development team provided technical explanations and how they are resilient to these kind of situations.

Findings

F-2024-4044Use of transfer() to Send Native Assets may Revert
Status
fixed
Severity

Low
F-2024-4057Redundant Token Transfer Results in Waste of Gas
Status
fixed
Severity

Observation
F-2024-4051Missing Events for Key Updates
Status
fixed
Severity

Observation
F-2024-4050Zero Address and Duplicated Entries can be Added into tokenList and protocols Arrays
Status
mitigated
Severity

Observation
F-2024-4049Minimum Staking Amount is not Compliant with Documentation
Status
fixed
Severity

Observation
F-2024-4048Single-Step Ownership Transfer Introduces Risks of Losing Ownership
Status
fixed
Severity

Observation
F-2024-4045Missing Check Results in Waste of Gas
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-4044Use of transfer() to Send Native Assets may Revert
fixed

Low
F-2024-4057Redundant Token Transfer Results in Waste of Gas
fixed

Observation
F-2024-4051Missing Events for Key Updates
fixed

Observation
F-2024-4050Zero Address and Duplicated Entries can be Added into tokenList and protocols Arrays
mitigated

Observation
F-2024-4049Minimum Staking Amount is not Compliant with Documentation
fixed

Observation
F-2024-4048Single-Step Ownership Transfer Introduces Risks of Losing Ownership
fixed

Observation
F-2024-4045Missing Check Results in Waste of Gas
fixed

Observation
1-7 of 7 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Severity Definitions

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Scope Details

Repositoryhttps://github.com/Nest-Layer/dropnest-protocol-contracts/→
Commit60be644381df46440497434ab1900258b17e05fc
Remediation commit84b87464abb914394f1099916841864189107472
WhitepaperN/A
Requirements./README
Technical Requirements./README

Contracts in Scope

src
DropnestStaking.sol - src › DropnestStaking.sol

Disclaimer