Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[L1] Elys | Elys Network | Nov24

Date:

Apr 7, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Elys team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.

Elys Network is a versatile DeFi platform built on the Cosmos SDK, offering a comprehensive suite of financial tools including AMMs, perpetual futures trading, leveraged liquidity pools, and stablecoin staking. It prioritizes a secure and transparent environment where users control their assets and participate in governance. With its modular design, Elys seamlessly integrates new features like trade shield, token deflation, and accounted pools, ensuring adaptability within the evolving DeFi landscape.

Document

NameBlockchain Protocol Review and Security Analysis Report for Elys
Audited ByTanuj Soni, Reza Mir
Approved ByNino Lipartiia
Websitehttps://elys.network/→
Changelog13/12/2024 - First Preliminary Report
24/01/2025 - Second Preliminary Report
29/01/2025 - Third Preliminary Report
07/03/2025 - Final Report
PlatformElys Network
LanguageGolang
TagsCosmos, IBC, Perpetual Trading, DeFi, Staking, Stablestake, Leverage LP
Methodologyhttps://hackenio.cc/blockchain_methodology→
  • Document

    Name
    Blockchain Protocol Review and Security Analysis Report for Elys
    Audited By
    Tanuj Soni, Reza Mir
    Approved By
    Nino Lipartiia
    Changelog
    13/12/2024 - First Preliminary Report
    24/01/2025 - Second Preliminary Report
    29/01/2025 - Third Preliminary Report
    07/03/2025 - Final Report
    Platform
    Elys Network
    Language
    Golang
    Tags
    Cosmos, IBC, Perpetual Trading, DeFi, Staking, Stablestake, Leverage LP

Review Scope

Repositoryhttps://github.com/elys-network/elys/→
Commit99bd50ba942ef856291aec1705e0d3acded58444

Audit Summary

24Total Findings
10Resolved
10Accepted
4Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report.

Documentation quality

  • User-facing documentation for features and use cases is well-organized and readily accessible.

  • Each custom module in the x directory is supported by detailed documentation, including READMEs, conceptual overviews, usage guides, keeper descriptions, and protobuf definitions.

  • However, several modules have outdated documentation that requires revisions to reflect the current implementation accurately.

  • The documentation lacks clarity on module interactions, particularly the integration of the AMM, Oracle pool, and perpetual module, as well as the execution and settlement processes for perpetual and spot orders.

  • Guides for setting up a local network using Docker or Ignite are available but require updates to address compatibility and build issues.

  • Documentation on off-chain components, such as the PriceFeeder, could be enhanced to include plans for decentralization and security measures as the Elys team transitions to the OjO network. Additionally, dependencies on third-party protocols, such as distributed oracles, should be thoroughly documented.

  • IBC Documentation: Cross-chain (IBC) integration processes require expanded documentation.

Code quality

  • The codebase adheres to Go programming best practices, supporting maintainability and optimal performance.

  • Custom modules include test cases; however, expanding coverage and diversifying scenarios would strengthen security and stability.

  • Certain functions exhibit high cyclomatic complexity, excessive length, and deeply nested structures, highlighting opportunities for refactoring.

Architecture quality

  • Elys Network utilizes the Cosmos SDK, a mature and widely-adopted framework for building blockchains, contributing to a robust technical foundation.

  • The Elys Network project exhibits a pragmatic architectural approach by inheriting and adapting complex modules from established projects like Osmosis and Evmos. This strategy accelerates development and leverages proven components for enhanced reliability.

  • The overall architecture quality is modular and pragmatic, prioritizing efficiency and leveraging existing solutions.

  • The architecture and design of external price feed to the system must be improved to ensure feeds are tamper-proof.

System Overview

Elys Network is a DeFi platform built using the Cosmos SDK and featuring a range of custom modules extending its core functionalities. This overview prioritizes the description of these custom modules and their interactions.

  1. estaking: Adds liquid staking, and burns EdenB tokens based on Elys staking changes.

  2. leveragelp: Enables leveraged liquidity pool positions (higher risk/reward).

  3. amm: Handles swaps via multiple pool types (standard, oracle), integrates with leveragelp/accountedpool, charges creation fees.

  4. accountedpool: Tracks pool balances for shielded AMM pools and impermanent loss protection.

  5. perpetual: Enables leveraged perpetual contracts with funding rates and liquidations.

  6. tradeshield: Security layer against trading exploits.

  7. transferhook: Enables IBC transfers with built-in token swaps.

  8. assetprofile: Manages asset-specific settings.

  9. parameter: Governance-controlled system parameter updates.

  10. oracle: Provides asset price feeds for valuations/liquidations.

  11. stablestake: Manages stablecoin staking/loans with dynamic rates.

  12. tier: User tiers with activity-based benefits.

  13. tokenomics: Controls token distribution/incentives.

  14. commitment: Manages user commitments and token locks.

  15. burner: Burns tokens regularly via epoch triggers.

  16. epochs: Schedules timed events/triggers.

  17. masterchef: Distributes liquidity provider rewards.

Risks

Due to the active development of the protocol, new features and code changes are continuously introduced. These ongoing modifications may inadvertently introduce vulnerabilities or inconsistencies that fall outside the scope of this audit.

Findings

F-2025-8500Critical MEV Vulnerability in TradeShield's Order Execution
Status
mitigated
Severity

Critical
F-2025-8461Inadequate Protections Against Funding Rate Manipulation
Status
mitigated
Severity

High
F-2025-8217Missing Liquidator Reward Implementation in Perpetual Trading System
Status
fixed
Severity

High
F-2024-7600Price Exploitation from Missing On-Chain TWAP Enforcement
Status
mitigated
Severity

High
F-2024-7467Vulnerable Dependencies
Status
fixed
Severity

High
F-2024-7593Price Manipulation and Feeder Centralization Risks
Status
fixed
Severity

Medium
F-2025-8435Insufficient Slippage Protection in IBC-Triggered Swaps
Status
accepted
Severity

Low
F-2025-8434Insufficient Market-Specific Leverage Limits and Missing Authority Controls
Status
fixed
Severity

Low
F-2025-8341Division by Zero Leading to Potential Panics
Status
fixed
Severity

Low
F-2025-8268Insufficient Protections in Elys Protocol AMM Logic
Status
accepted
Severity

Low
Code
―
Title
Status
Severity
F-2025-8500Critical MEV Vulnerability in TradeShield's Order Execution
mitigated

Critical
F-2025-8461Inadequate Protections Against Funding Rate Manipulation
mitigated

High
F-2025-8217Missing Liquidator Reward Implementation in Perpetual Trading System
fixed

High
F-2024-7600Price Exploitation from Missing On-Chain TWAP Enforcement
mitigated

High
F-2024-7467Vulnerable Dependencies
fixed

High
F-2024-7593Price Manipulation and Feeder Centralization Risks
fixed

Medium
F-2025-8435Insufficient Slippage Protection in IBC-Triggered Swaps
accepted

Low
F-2025-8434Insufficient Market-Specific Leverage Limits and Missing Authority Controls
fixed

Low
F-2025-8341Division by Zero Leading to Potential Panics
fixed

Low
F-2025-8268Insufficient Protections in Elys Protocol AMM Logic
accepted

Low
1-10 of 24 findings

Findings like these can secure your blockchain.

Appendix 1. Severity Definitions

Severity

Description

Critical
Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

High
High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

Medium
Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

Low
Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
  • Severity

    Critical

    Description

    Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

    Severity

    High

    Description

    High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

    Severity

    Medium

    Description

    Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

    Severity

    Low

    Description

    Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.

Appendix 2. Scope

The scope of the project includes the following components from the provided repository:

Scope Details

Repositoryhttps://github.com/elys-network/elys/→
Commit99bd50ba942ef856291aec1705e0d3acded58444

Components in Scope

  1. Cosmos SDK Core App

  2. Cosmos fork review

  3. RPC

  4. Cryptography and keys

  5. Custom Modules:

    1. x/accountedpool

    2. x/commitment

    3. x/masterchef

    4. x/stablestake

    5. x/transferhook

    6. x/amm

    7. x/epochs

    8. x/oracle

    9. x/tier

    10. x/assetprofile

    11. x/estaking

    12. x/parameter

    13. x/tokenomics

    14. x/burner

    15. x/leveragelp

    16. x/perpetual

    17. x/tradeshield

Assets in Scope

accountedpool - accountedpool
amm - amm
assetprofile - assetprofile
burner - burner
Code Quality - Code Quality
commitment - commitment
Core App - Core App
Cryptography and keys - Cryptography and keys
Dependencies - Dependencies
epochs - epochs
estaking - estaking
leveragelp - leveragelp
masterchef - masterchef
oracle - oracle
parameter - parameter
perpetual - perpetual
RPC - RPC
stablestake - stablestake
tier - tier
tokenomics - tokenomics
tradeshield - tradeshield
transferhook - transferhook

Disclaimer