Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] Gotbit | Bridge | May2023

Date:

Jun 7, 2023

Table of Content

→Introduction
→Audit Summary
→Document Information
→System Overview
→Executive Summary
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Gotbit team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

GotBit Labs is a provider of web3 development and consulting services. They perform in diverse areas within the web3 ecosystem, including blockchain technology, crafting decentralized applications (DApps), pioneering contract development, and other associated fields.

titlecontent
PlatformEVM
LanguageSolidity
TagsBridge
Timeline17/05/2023 - 09/06/2023
Methodologyhttps://hackenio.cc/sc_methodology→

    Review Scope

    Repositoryhttps://github.com/GotBit/bridge→
    Commit82eb229f24dbb0d9a30203886420d6bc62cedf95

    Audit Summary

    Total10/10
    Security Score

    10/10

    Test Coverage

    100%

    Code Quality Score

    10/10

    Documentation Quality Score

    10/10

    20Total Findings
    14Resolved
    0Accepted
    6Mitigated

    The system users should acknowledge all the risks summed up in the risks section of the report

    Document Information

    This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.

    The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.

    Document

    NameSmart Contract Code Review and Security Analysis Report for Gotbit
    Audited ByHacken
    Changelog22/05/2023 - Initial Review
    07/06/2023 - Second Review
    09/06/2023 - Third Review
    • Document

      Name
      Smart Contract Code Review and Security Analysis Report for Gotbit
      Audited By
      Hacken
      Changelog
      22/05/2023 - Initial Review
      07/06/2023 - Second Review
      09/06/2023 - Third Review

    System Overview

    The audit of the scope consists of a bridge contract for ERC20 transfers between chains. The aim is to implement a bridge that provides transfers both between EVM chains and from EVM to non-EVM chains and vice versa.

    The system works using signature verification using the EIP712 standard. The transactions are signed by a relayer to be ready for fulfillment.

    The files in the scope:

    • BridgeAssist.sol - The bridge contract that records requests for sending tokens between chains, and fulfills requests if signed by the relayer.

    Privileged roles

    • Relayer: is the backend contract address, which is used for signing transactions to fulfill.

    • DefaultAdmin: can grant/revoke all roles, can set fee, feeWallet, limitPerSend, pause/unpause contract and withdraw tokens from contract.

    Executive Summary

    Documentation quality

    The total Documentation quality score is 10 out of 10.

    • Functional requirements are provided.

    • Technical description is provided.

    • Description of the development environment is given.

    • NatSpec is present.

    Code quality

    The total Code quality score is 10 out of 10.

    • The development environment is configured.

    Test coverage

    Code coverage of the project is 100% (branch coverage).

    • Deployment and basic user interactions are covered with tests.

    • Negative cases coverage is present.

    • Interactions by several users are not tested thoroughly.

    Security score

    Upon auditing, the code was found to contain 1 critical, 5 high, 6 medium, and 4 low severity issues. Out of these, 10 issues have been addressed and resolved, leading to a Security score of 10 out of 10.

    All identified issues are detailed in the “Findings” section of this report.

    Summary

    The comprehensive audit of the customer's smart contract yields an overall score of 10. This score reflects the combined evaluation of documentation, code quality, test coverage, and security aspects of the project.

    Risks

    The project is highly centralized, with a Relayer role that controls the release of funds on each chain. If the private keys of the Relayer are lost or there is malicious intent, the protocol could be vulnerable to attack.

    The fulfill() function has the whenNotPaused modifier, if the contract is paused, users will not be able to receive their funds.

    There is a withdraw() function for the Admin role to withdraw any tokens from the contract, including the token that is bridged. If compromised, all tokens stored inside bridge contracts will be lost.

    The bridge fee can be changed between sending and fulfilling and has an upper limit of 99.99%. This may lead to the losses of funds during bridging.

    The chains have to be manually whitelisted by the admin and can be removed at any moment, rendering all pending transactions unclaimable.

    The bridge supports fee on transfers tokens and reflective tokens only if the bridge is excluded from the fees.

    The fee can be changed at any time by the owner, transfers that are already started, but not completely fulfilled will have the new fee value applied.

    Findings

    F-2023-0678Funds Lock; Denial of Service
    Status
    fixed
    Severity

    Critical
    F-2023-0683Inconsistent Data
    Status
    fixed
    Severity

    High
    F-2023-0682Funds Lock
    Status
    mitigated
    Severity

    High
    F-2023-0681Inconsistent Data
    Status
    mitigated
    Severity

    High
    F-2023-0680Undocumented Functionality
    Status
    mitigated
    Severity

    High
    F-2023-0679Token Supply Manipulation
    Status
    mitigated
    Severity

    High
    F-2023-0689Denial of Service
    Status
    fixed
    Severity

    Medium
    F-2023-0688Highly Permissive Role Access
    Status
    mitigated
    Severity

    Medium
    F-2023-0687Undocumented Functionality
    Status
    fixed
    Severity

    Medium
    F-2023-0686Coarse-grained Access Control
    Status
    mitigated
    Severity

    Medium
    Code
    ―
    Title
    Status
    Severity
    F-2023-0678Funds Lock; Denial of Service
    fixed

    Critical
    F-2023-0683Inconsistent Data
    fixed

    High
    F-2023-0682Funds Lock
    mitigated

    High
    F-2023-0681Inconsistent Data
    mitigated

    High
    F-2023-0680Undocumented Functionality
    mitigated

    High
    F-2023-0679Token Supply Manipulation
    mitigated

    High
    F-2023-0689Denial of Service
    fixed

    Medium
    F-2023-0688Highly Permissive Role Access
    mitigated

    Medium
    F-2023-0687Undocumented Functionality
    fixed

    Medium
    F-2023-0686Coarse-grained Access Control
    mitigated

    Medium
    1-10 of 20 findings

    Identify vulnerabilities in your smart contracts.

    Appendix 1. Severity Definitions

    When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

    Reference on how risk scoring is done is available through the repository in our Github organization:

    Severity

    Description

    Critical
    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    High
    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Medium
    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Low
    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
    • Severity

      Critical

      Description

      Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

      Severity

      High

      Description

      High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

      Severity

      Medium

      Description

      Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

      Severity

      Low

      Description

      Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

    Appendix 2. Scope

    The scope of the project includes the following smart contracts from the provided repository:

    Scope Details

    Repositoryhttps://github.com/GotBit/bridge→
    Commit82eb229f24dbb0d9a30203886420d6bc62cedf95
    WhitepaperNot provided
    RequirementsProvided→
    Technical RequirementsProvided→

    Contracts in Scope

    contracts
    BridgeAssist.sol - contracts › BridgeAssist.sol

    Disclaimer