Introduction
We express our gratitude to the Interport team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
Interport is a decentralized exchange that allows cross-chain swaps.
| title | content |
|---|---|
| Platform | EVM |
| Language | Solidity |
| Tags | ERC20; Staking; Bridge; DEX |
| Timeline | 08/12/2022 - 22/03/2023 |
| Methodology | https://hackenio.cc/sc_methodology→ |
Review Scope | |
|---|---|
| Repository | https://github.com/Interport-Finance/contracts-interport→ |
| Commit | 2e6a44647233580466f672fa6ca3f88ac109f716 |
Review Scope
- Commit
- 2e6a44647233580466f672fa6ca3f88ac109f716
Audit Summary
10/10
100%
10/10
10/10
The system users should acknowledge all the risks summed up in the risks section of the report
Document Information
This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.
The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for Interport |
| Audited By | Hacken |
| Website | https://interport.fi→ |
| Changelog | 18/01/2023 - Initial Review |
| 06/03/2023 - Second Review | |
| 22/03/2023 - Third Review |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for Interport
- Audited By
- Hacken
- Website
- https://interport.fi→
- Changelog
- 18/01/2023 - Initial Review
- 06/03/2023 - Second Review
- 22/03/2023 - Third Review
System Overview
Interport is a decentralized exchange that allows cross-chain swaps:
Role Contracts — abstract access control contracts. Allow update/view role for owners.
BalanceManagement — an abstract contract that allows to withdraw unexpected tokens from contract balance.
CallerGuard — an abstract contract with a functionality to decline calls from non-whitelisted contracts.
Pausable — an abstract contract that allows to pause/unpause critical functionality.
MultichainTokenBase — an abstract contract with a mint and burnFrom functionality.
VaultBase — an abstract ERC20-vault contract that inherits MultichainTokenBase. Provides the ability to deposit/withdraw funds.
Vault — a contract that inherits VaultBase. Functionality:
Converting variable token to the main vault asset.
Withdrawing funds by asset spenders.
VariableToken — an ERC20 contract used in Vault, based on MultichainTokenBase.
VariableBalanceRecords — a contract for storing temporary user balances at ActionExecutor. It is fully controlled by the ActionExecutor.
ActionExecutor — a contract for interaction of cross-chain swaps. Functionality:
executeLocal — executes the single-chain token swap.
execute — executes a cross-chain token swap.
claimVariableToken — allows a variable token claim from the user's variable balance.
convertVariableBalanceToVaultAsset — a vault asset claim by user's variable balance.
messageFeeEstimate — a cross-chain message fee estimation.
calculateLocalAmount — a swap result amount for single-chain actions, taking the system fee into account.
calculateVaultAmount — a swap result amount for cross-chain actions, taking the system fee into account.
variableBalance — the variable balance of the account.
handleExecutionPayload — a cross-chain message handler on the target chain.
ActionExecutorRegistry — a storage contract for ActionExecutor.
GatewayBase \- a base contract for the AnyCallV7 and LayerZero Gateways that implements shared logic between child contracts. Manages list of peers on other chains.
AnyCallV7Gateway - a contract that implements the cross-chain messaging logic specific to AnyCall v7. It is an intermediate contract between the ActionExecutor and the AnyCall protocol.
LayerZeroGateway - a contract that implements the cross-chain messaging logic specific to LayerZero. It is an intermediate contract between the ActionExecutor and the LayerZero protocol.
InterportToken — a simple ERC-20 token with unlimited minting. The contract owner can specify a multichainRouter address, which is allowed to burn the user’s tokens. It has the following attributes:
Name: Interport Token
Symbol: ITP
Decimals: 18
Total supply: unlimited
Buyback — a contract for buyback fee receival. Received funds are swapped to buyback tokens.
FeeMediator — a contract for fee processing. The contract balance is distributed to the destinations based on proportion. The proportion is defined by a contract manager. Fee destinations:
Buyback contract
FeeDistributionLPLockers contract
FeeDistributionITPLockers contract
Treasury contract
StablecoinFarm — staking/vesting contract. Functionality:
stake — allows staking funds for the reward.
withdraw — allows withdrawing staked funds.
emergencyWithdraw — allows withdrawing staked funds and dropping obtained rewards.
setRewardTokenPerSecond — allows managers to set the contract APR.
add — allows new staking pool creation.
set — allows staking pool APR share updation.
vest — allows vesting the pending rewards.
withdrawVestedRewards — allows withdrawing the vested rewards.
exitEarly — allows withdrawing vested rewards immediately but applies a penalty.
lockVesting — allows locking vested rewards on an ITP revenue contract.
lockPending — allows locking pending rewards on an ITP revenue contract.
RevenueShareBase — an abstract revenue contract. Functionality:
withdraw — allows withdrawing unlocked rewards.
claimableRewards — returns obtained rewards for vestings.
getReward — allows withdrawing pending rewards.
ITPRevenueShare — a revenue contract based on RevenueShareBase. Functionality:
lock — allows locking funds to obtain rewards.
lock — allows lockers locking funds on behalf of other users.
LPRevenueShare — a revenue contract based on RevenueShareBase. Functionality:
lock — allows locking funds to obtain rewards.
Privileged roles
The InterportToken contract has the following privileged roles:
Owner
Can mint and burn tokens.
Can assign MultichainRouter role.
Can transfer ownership to any non zero address.
MultichainRouter
Can mint and burn tokens.
The Vault contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can assign an AssetSpender role.
can assign a MultichainRouter role.
can set a variable token.
can enable or disable variable token repayments.
can pause or unpause contract functionality.
Multichain router:
can mint and burn (using allowance) tokens.
Asset spender:
can withdraw any amount of tokens from the vault.
The VariableBalanceRecords contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can withdraw any token from the contract.
can set an ActionExecutor role.
ActionExecutor:
can modify the variable token balance for a specific user.
The VariableToken contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can assign a minter role.
can assign a burner role.
can assign a multichain router role.
can withdraw any token from the contract.
can pause or unpause contract functionality.
Minter:
can mint variable tokens if useExplicitAccess is enabled.
Burner:
can burn (using allowance) variable tokens if useExplicitAccess is enabled.
MultichainRouter:
can mint and burn (using allowance) variable tokens.
The LayerZeroGateway contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can assign a client role.
can specify a Layer Zero proxy address.
can add/remove peers.
can add/remove chain id pairs.
can change target gas.
can withdraw any token from the contract.
can pause or unpause contract functionality.
Client:
can send a message to layer zero proxy.
Layer Zero endpoint:
can bring cross-chain message to the system.
The AnyCallV7Gateway contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can withdraw any token from the contract.
can set any call proxy.
can assign client role.
can add/remove peers.
can pause or unpause contract functionality.
can change target gas.
Client:
can send a message to call proxy.
Any Call endpoint:
can bring cross-chain message to the system.
The ActionExecutorRegistry contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can change target gas.
can withdraw any token from the contract.
can add/remove gateway address.
can add/remove swap routers.
can add or update a registered swap router transfer contract address.
can add/remove vaults.
can set/unset vault decimals.
can specify fees.
can specify fee collector addresses.
can add/remove from the whitelist.
can specify min and max swap amount.
The ActionExecutor contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can withdraw any token from the contract.
can set a registry address.
can set a variable balance records address.
can pause or unpause contract functionality.
The StablecoinFarm contract has the following privileged roles:
Owner:
can assign a manager role.
can specify an ITPRevenueShare contract address.
can specify a LPRevenueShare contract address.
can specify a percent share for early exist.
Manager:
can withdraw any token from the contract.
can specify a rewards token per second value.
can add new pools.
can change the end time.
can update reward token allocation point per pool.
can pause or unpause contract functionality.
The LPRevenueShare contract have the following privileged roles:
Owner:
can assign a manager role.
can enable public exit.
can add reward tokens addresses.
Manager:
can withdraw any token from the contract.
can pause or unpause contract functionality.
The ITPRevenueShare contract have the following privileged roles:
Owner:
can assign a manager role.
can enable public exit.
can add reward tokens addresses.
can assign or remove lockers roles.
Manager:
can withdraw any token from the contract.
can pause or unpause contract functionality.
Locker:
can lock tokens to receive rewards.
The FeeMediator contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can withdraw any token from the contract.
can specify a buyback address.
can specify fee distribution addresses.
can specify a treasury address.
can specify buyback, ITPLockers and LPLockers distribution percents.
can specify assets addresses.
can initiate fees processing.
The Buyback contract has the following privileged roles:
Owner:
can assign a manager role.
Manager:
can withdraw any token from the contract.
can specify a router to native and router from native addresses.
can specify swap tolerance.
Executive Summary
Documentation quality
The total Documentation quality score is 10 out of 10.
Technical requirements properly describe the system.
Functional requirements of the system are provided.
Code quality
The total Code quality score is 10 out of 10.
The Development environment is configured.
The System is well architected and divided by multiple components, following the single responsibility principle.
Test coverage
Code coverage of the project is 100% (branch coverage).
Code is properly covered with tests.
Security score
Upon auditing, the code was found to contain 1 critical, 8 high, 14 medium, and 17 low severity issues. Out of these, 34 issues have been addressed and resolved, leading to a security score of 10 out of 10.
All identified issues are detailed in the “Findings” section of this report.
Summary
The comprehensive audit of the customer's smart contract yields an overall score of 10. This score reflects the combined evaluation of documentation, code quality, test coverage, and security aspects of the project.
Risks
The bridging logic highly relies on third-party integrations (LayerZero → and Multichain →), they could have their own vulnerabilities that are out of the audit’s scope.
In case a transaction fails on the target chain, the off-chain service should refund tokens on the initial chain. The service is out of the audit’s scope.
The system highly depends on the owner and managers. In case of a private keys leak, unauthorized accounts may obtain access to user funds.
The bridging logic uses different DEXes to swap tokens. The DEXes are out of the audit’s scope and could have security vulnerabilities.
Funds deposited to vaults may be withdrawn by the system, so the depositors may need to wait for liquidity in an original chain, or bridge their iUSDT/iUSDC to another chain and withdraw funds there. In the scope of the audit, it’s not possible to verify if the system would have a possibility to bridge iUSDT/iUSDC tokens.
Contracts may be paused and user funds may be locked.
According to the MultiChain standard, the InterportToken contract system owners are able to mint and burn any amount of user funds.
The system may be vulnerable to interactions with multiple endpoint tokens. Multiple endpoint tokens may be unexpectedly withdrawn by system managers.
The reward token should not be collided with any staking token on the StablecoinFarm contract to keep user funds safe.
The StablecoinFarm contract may have not enough funds to satisfy earned rewards. However, it is possible to withdraw staked funds at any moment and get the earned value after the contract is fulfilled.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2022-1835 | Double spending; Data Consistency | fixed | Critical | |
| F-2022-1843 | Requirement Violation | mitigated | High | |
| F-2022-1842 | Highly Permissive Role Access | fixed | High | |
| F-2022-1841 | Highly Permissive Role Access | fixed | High | |
| F-2022-1840 | Undocumented Behavior; Requirement Violation | fixed | High | |
| F-2022-1839 | Funds Lock; Requirements violation | fixed | High | |
| F-2022-1838 | Invalid Calculations | fixed | High | |
| F-2022-1837 | Insufficient balance; Requirement violation | mitigated | High | |
| F-2022-1836 | Denial of Service Vulnerability | fixed | High | |
| F-2022-1858 | Requirement Violation | fixed | Medium |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/Interport-Finance/contracts-interport→ |
| Commit | c8bf3ea58469c65fc2210ee750a904011eded131 |
| Whitepaper | Provided→ |
| Requirements | Provided→ |
| Technical Requirements | Provided |