Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] GraFun | GraFun Contracts | Sep2024

Date:

Sep 25, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Potential Risks
→Findings
→Appendix 1. Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the GraFun team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

The GraFun provides Token Sales protocol that is an Initial Coin Offering (ICO) solution, allowing users to buy and sell tokens, and eventually it deploys PancakeSwap pair for token.

Document

NameSmart Contract Code Review and Security Analysis Report for GraFun
Audited ByGrzegorz Trawinski
Approved ByAtaberk Yavuzer
Websitehttps://gra.fun/→
Changelog20/09/2024 - Preliminary Report
25/09/2024 - Final Report
PlatformBNB Chain
LanguageSolidity
TagsInitial Coin Offering, ICO, Token Sales, ERC20, PancakeSwap
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for GraFun
    Audited By
    Grzegorz Trawinski
    Approved By
    Ataberk Yavuzer
    Changelog
    20/09/2024 - Preliminary Report
    25/09/2024 - Final Report
    Platform
    BNB Chain
    Language
    Solidity
    Tags
    Initial Coin Offering, ICO, Token Sales, ERC20, PancakeSwap

Review Scope

RepositoryHidden
Commit504724739624914f0664f6a55e9b466cc629c4c9, dev branch
Remediation commit1fab268195ea8fb94b2d921246fa450aa8f7addc
  • Review Scope

    Repository
    Hidden
    Commit
    504724739624914f0664f6a55e9b466cc629c4c9, dev branch
    Remediation commit
    1fab268195ea8fb94b2d921246fa450aa8f7addc

Audit Summary

12Total Findings
4Resolved
8Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • The protocol documentation was not provided.

Code quality

  • The code represents clear architecture of the solution.

  • No NatSpecs were provided.

Test coverage

  • Code coverage of the project is 73.53% (branch coverage).

System Overview

The Token Sales is an Initial Coin Offering (ICO) solution with the following contracts:

  • Token  - a contract representing the ERC20 token that is a subject of the Initial Coin Offering. The contract instance is created by means of the TokenSaleFactory contract.

  • TokenSaleFactory - a contract that allows users to start new Initial Coin Offering, buy and sell tokens, redeem purchases after token sale's deadline. It also deploy the PancakeSwap instances.

  • TokenSaleHelpers - a library with a set of functions used by the aforementioned contracts.

Privileged roles

  • The owner of the TokenSaleFactory contract can upgrade the contract.

Potential Risks

Potentially Impossible Redemption: The protocol is designed to allow buy and sell tokens until the token sale period ends. The sale period ends either when PancakeSwap instance is deployed or deadline is reached. Whenever users transfer tokens between accounts, they lose possibility to redeem tokens. In the event of token sale period end without PancakeSwap instance deployment, users who did not sell tokens previously will likely encounter financial loss, as tokens held may have no economic value.

Single Points of Failure and Control: The project is fully or partially centralized, introducing single points of failure and control. This centralization can lead to vulnerabilities in decision-making and operational processes, making the system more susceptible to targeted attacks or manipulation.

Administrative Key Control Risks: The digital contract architecture relies on administrative keys for critical operations. Centralized control over these keys presents a significant security risk, as compromise or misuse can lead to unauthorized actions or loss of funds.

Single Entity Upgrade Authority: The token ecosystem grants a single entity the authority to implement upgrades or changes. This centralization of power risks unilateral decisions that may not align with the community or stakeholders' interests, undermining trust and security.

Flexibility and Risk in Contract Upgrades: The project's contracts are upgradable, allowing the administrator to update the contract logic at any time. While this provides flexibility in addressing issues and evolving the project, it also introduces risks if upgrade processes are not properly managed or secured, potentially allowing for unauthorized changes that could compromise the project's integrity and security.

Absence of Upgrade Window Constraints: The contract suite allows for immediate upgrades without a mandatory review or waiting period, increasing the risk of rapid deployment of malicious or flawed code, potentially compromising the system's integrity and user assets.

Findings

F-2024-6210Tokens transfer causes fund loss if token sale is not finished
Status
fixed
Severity

High
F-2024-6185Arbitrary referralLink can be provided to collect fee
Status
accepted
Severity

Medium
F-2024-6183Excessive protocol fee accounting possible
Status
fixed
Severity

Medium
F-2024-6209Lack of emergency stop mechanism
Status
accepted
Severity

Low
F-2024-6191Lack of two-step ownership transfer pattern
Status
accepted
Severity

Low
F-2024-6187The finishingTime parameter lacks input validation
Status
fixed
Severity

Low
F-2024-6193Lack of IERC20 transfer/transferFrom return value check
Status
accepted
Severity

Observation
F-2024-6189Lack of Monitoring on Key Functions
Status
accepted
Severity

Observation
F-2024-6186The RedeemBalance struct has typo
Status
accepted
Severity

Observation
F-2024-6182TokenSaleFactory implementation is not disabled
Status
accepted
Severity

Observation
Code
―
Title
Status
Severity
F-2024-6210Tokens transfer causes fund loss if token sale is not finished
fixed

High
F-2024-6185Arbitrary referralLink can be provided to collect fee
accepted

Medium
F-2024-6183Excessive protocol fee accounting possible
fixed

Medium
F-2024-6209Lack of emergency stop mechanism
accepted

Low
F-2024-6191Lack of two-step ownership transfer pattern
accepted

Low
F-2024-6187The finishingTime parameter lacks input validation
fixed

Low
F-2024-6193Lack of IERC20 transfer/transferFrom return value check
accepted

Observation
F-2024-6189Lack of Monitoring on Key Functions
accepted

Observation
F-2024-6186The RedeemBalance struct has typo
accepted

Observation
F-2024-6182TokenSaleFactory implementation is not disabled
accepted

Observation
1-10 of 12 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Definitions

Severities

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

Potential Risks

The "Potential Risks" section identifies issues that are not direct security vulnerabilities but could still affect the project’s performance, reliability, or user trust. These risks arise from design choices, architectural decisions, or operational practices that, while not immediately exploitable, may lead to problems under certain conditions. Additionally, potential risks can impact the quality of the audit itself, as they may involve external factors or components beyond the scope of the audit, leading to incomplete assessments or oversight of key areas. This section aims to provide a broader perspective on factors that could affect the project's long-term security, functionality, and the comprehensiveness of the audit findings.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Scope Details

RepositoryHidden
Commit5047247
Remediation commit1fab2681
WhitepaperN/A
RequirementsN/A
Technical RequirementsN/A
  • Scope Details

    Repository
    Hidden
    Commit
    5047247
    Remediation commit
    1fab2681
    Whitepaper
    N/A
    Requirements
    N/A
    Technical Requirements
    N/A

Contracts in Scope

contracts
Token.sol - contracts › Token.sol
TokenSaleFactory.sol - contracts › TokenSaleFactory.sol
TokenSaleHelpers.sol - contracts › TokenSaleHelpers.sol
libs
SqrtPriceX96.sol - contracts › libs › SqrtPriceX96.sol

Disclaimer