Introduction
We express our gratitude to the Dropnest team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
The DropnestStaking protocol is a smart contract system for EVM chains. It is designed to manage deposits for the Dropnest protocol and record the deposits via emitting events into the blockchain. Deposited tokens are then sent to external protocols for farming.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for Dropnest |
| Audited By | David Camps Novi, Viktor Lavrenenko |
| Approved By | Przemyslaw Swiatowiec |
| Website | https://www.dropnest.xyz/→ |
| Changelog | 27/06/2024 - Preliminary Report; 04/07/2024 - Final Report |
| Platform | Ethereum, Base, Optimism, Arbitrum, Linea, Blast, Polygon |
| Language | Solidity |
| Tags | Staking, Farming |
| Methodology | https://hackenio.cc/sc_methodology→ |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for Dropnest
- Audited By
- David Camps Novi, Viktor Lavrenenko
- Approved By
- Przemyslaw Swiatowiec
- Website
- https://www.dropnest.xyz/→
- Changelog
- 27/06/2024 - Preliminary Report; 04/07/2024 - Final Report
- Platform
- Ethereum, Base, Optimism, Arbitrum, Linea, Blast, Polygon
- Language
- Solidity
- Tags
- Staking, Farming
- Methodology
- https://hackenio.cc/sc_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/Nest-Layer/dropnest-protocol-contracts/→ |
| Commit | 60be644381df46440497434ab1900258b17e05fc |
Review Scope
- Commit
- 60be644381df46440497434ab1900258b17e05fc
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
Functional requirements are limited.
Basic system description is provided.
System roles are explained.
Technical description is complete.
NatSpec is provided.
Run instructions are present.
Code quality
The development environment is configured.
Inefficient gas model: F-2024-4045, F-2024-4050.
Best practices are followed.
Test coverage
Code coverage of the project is 94.4% (branch coverage).
Deployment and basic user interactions are covered with tests.
Negative cases coverage is extensively tested.
System Overview
The DropnestStaking protocol is a smart contract system for EVM chains. It is designed to manage deposits for the Dropnest protocol and record the deposits via emitting events into the blockchain. Deposited tokens are then sent to external protocols for farming.
Staking: Users can stake their ETH or predetermined ERC20 tokens on a specific protocol. The staked tokens are transferred to the farmer address of the protocol.
Multiple Staking: Users can also stake their ETH or ERC20 tokens on multiple protocols at once. The total amount of tokens staked should be equal to the sum of the individual amounts staked on each protocol.
Privileged roles
The owner of the contract can
Add new protocols or update the farmer address for existing ones.
Pause and unpause the contract.
Set the status of a protocol from active to inactive, and vice-versa.
Risks
The audited contract DropnestStaking is highly centralized, introducing single points of failure and control. This centralization can lead to vulnerabilities in decision-making and operational processes, making the system more susceptible to targeted attacks or manipulation. The centralization is expressed by the reliance on the protocol owners for:
Tracking deposits from users into the protocol, and subsequent calculation and management of staking rewards and users' funds, off-chain.
Managing interactions with the farming protocols used by the system, off-chain.
Pausing and unpausing the contract.
Adding and removing supported tokens.
Managing the farming protocols' statuses and addresses.
The digital contract architecture relies on administrative keys for critical operations. Centralized control over these keys presents a significant security risk, as compromise or misuse can lead to unauthorized actions or loss of funds. Such operations are:
Pause and unpause the contract.
Add and remove supported tokens.
Manage the farming protocols' statuses and addresses.
The implemented farmAddresses and supportedTokens logic highly depends on external contracts not covered by the audit. This reliance introduces risks if these external contracts are compromised or contain vulnerabilities, affecting the audited project's integrity. More details about such contracts and their usage can be found in the project README.
The DropnestStaking contract contains the staking functionality of the system, through which users' deposits are tracked using the events Deposited and ERC20Deposited. The amounts are tracked off-chain, where additional calculations take place in order to complete the staking functionality (balance tracking, rewards, etc.).
Although the team does not currently plan to support fee-on-transfer tokens, if such kind of tokens (or any other kind of token were the input amount and received amount could be different) were introduced in the system, the off-chain part of the protocol should be adapted. Otherwise, there could be mismatches between the tracked amount emitted by the events and the actual transferred amount, resulting in wrong calculations and balance tracking in the system. The project README provides further insights on this topic, where the development team provided technical explanations and how they are resilient to these kind of situations.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-4044 | Use of transfer() to Send Native Assets may Revert | fixed | Low | |
| F-2024-4057 | Redundant Token Transfer Results in Waste of Gas | fixed | Observation | |
| F-2024-4051 | Missing Events for Key Updates | fixed | Observation | |
| F-2024-4050 | Zero Address and Duplicated Entries can be Added into tokenList and protocols Arrays | mitigated | Observation | |
| F-2024-4049 | Minimum Staking Amount is not Compliant with Documentation | fixed | Observation | |
| F-2024-4048 | Single-Step Ownership Transfer Introduces Risks of Losing Ownership | fixed | Observation | |
| F-2024-4045 | Missing Check Results in Waste of Gas | fixed | Observation |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/Nest-Layer/dropnest-protocol-contracts/→ |
| Commit | 60be644381df46440497434ab1900258b17e05fc |
| Remediation commit | 84b87464abb914394f1099916841864189107472 |
| Whitepaper | N/A |
| Requirements | ./README |
| Technical Requirements | ./README |
Scope Details
- Commit
- 60be644381df46440497434ab1900258b17e05fc
- Remediation commit
- 84b87464abb914394f1099916841864189107472
- Whitepaper
- N/A
- Requirements
- ./README
- Technical Requirements
- ./README