Introduction
We express our gratitude to the LitLab Games team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
LitLab Games generates sustainable environments and new monetization models through LITT adoption in all of our published games, providing blockchain tools with a full web 2.0 experience.
| title | content |
|---|---|
| Platform | EVM |
| Language | Solidity |
| Tags | ERC20; Staking; Vesting; Gaming |
| Timeline | 14/03/2023 - 05/05/2023 |
| Methodology | https://hackenio.cc/sc_methodology→ |
Review Scope | |
|---|---|
| Repository | https://github.com/jgomes79/LitLabGames→ |
| Commit | 1b7b59ccdb29c3d95ebdb9080819abbb707a93ba |
Review Scope
- Repository
- https://github.com/jgomes79/LitLabGames→
- Commit
- 1b7b59ccdb29c3d95ebdb9080819abbb707a93ba
Audit Summary
10/10
49.16%
8/10
7/10
The system users should acknowledge all the risks summed up in the risks section of the report
Document Information
This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.
The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for LitLab Games |
| Audited By | Hacken |
| Website | https://litlabgames.com→ |
| Changelog | 21/03/2023 - Initial Review |
| 13/04/2023 - Second Review | |
| 05/05/2023 - Third Review |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for LitLab Games
- Audited By
- Hacken
- Website
- https://litlabgames.com→
- Changelog
- 21/03/2023 - Initial Review
- 13/04/2023 - Second Review
- 05/05/2023 - Third Review
System Overview
LitLab Games is a mixed-purpose system with the following contracts:
LitlabGamesToken — ERC-20 permit token that mints all initial supply to a deployer. Allows burning mechanisms and implements an antisnipe functionality from Gotbit →. It has the following attributes:
Name: LitlabToken
Symbol: LITT
Decimals: 18
Total supply: 3b tokens.
LitlabGamesToken — an interface for a burnable ERC20 token.
Ownable – an abstract smart contract that implements the possibility of ownership.
LitlabPreStakingBox – a staking smart contract, which is used to issue an initial token offer to a limited number of users. Staking participants can only be added by the owner. Also, only the owner assigns the amount of the reward received as a result of staking.
LITTAdvisorsTeam – a vesting smart contract which is used to distribute tokens for advisors and the team. The smart contract ses a linear distribution of tokens. A team needs to verify three different wallets in order to withdraw their rewards.
LITTVestingContract – a vesting smart contract which is used to distribute the supply of tokens in accordance with the whitepaper and distribution schedule.
CyberTitansGame – a smart contract used for creating and managing games. The game in this case is an abstract thing, it stores a list of players and winners. Winners are chosen outside the blockchain. The contract calculates and sends the rewards for the winners.
CyberTitansTournament – a smart contract used for creating and managing tournaments. The tournaments in this case is an abstract thing, it stores a list of participants, calculate rewards according to the amount of players. Anyone can join the tournament, winners are chosen outside the blockchain.
LitlabContext – an instance of simple ERC2771Context smart contract.
LitlabForwarder – a forwarder smart contract which will be used for metatransactions.
Privileged roles
The owner of the CyberTitansGame contract can change addresses of manager role, address for fee collecting, native game ERC20 token address. The owner can change game winners, fees percentage, withdrawal delay, maximum bet amount, pause/unpause smart contract and withdraw any amount of tokens from the contract.
The manager of the CyberTitansGame can create and end games.
The owner of the CyberTitansTournament contract can change addresses of manager role, address for fee collecting, native game ERC20 token address. The owner can change reward matrix, fees percentage, pause/unpause smart contract and withdraw any amount of tokens from the contract.
The manager of the CyberTitansGame can start and end tournaments.
The owner of the LitlabGamesToken can disable antisnipe system, which is not in the scope.
The owner of the LitlabPreStakingBox can add new investors to staking. The owner can withdraw any amount of tokens from the contract.
The owner of LITTAdvisorsTeam can set start time of vesting, add and remove advisors, set advisors’ rewards, set approval wallets for team rewards withdrawing and change address of team wallet. The owner can withdraw any amount of tokens from the contract.
The owner of LITTVestingContract can set the start time of vesting, change the company wallet. The owner can withdraw any amount of tokens from the contract.
Recommendations
Owner private keys should be ⅗ multi-sig.
Test coverage should be updated.
Executive Summary
Documentation quality
The total Documentation quality score is 7 out of 10.
Overall system requirements are provided.
No run instructions.
Technical specification is provided.
NatSpec is not fully provided.
Code quality
The total Code quality score is 8 out of 10.
Development environment is not configured.
Test coverage
Code coverage of the project is 49.16% (branch coverage).
Test coverage is insufficient.
Security score
Upon auditing, the code was found to contain 6 critical, 17 high, 20 medium, and 20 low severity issues. Out of these, 53 issues have been addressed and resolved, leading to a Security score of 10 out of 10.
All identified issues are detailed in the “Findings” section of this report.
Summary
The comprehensive audit of the customer's smart contract yields an overall score of 7.2. This score reflects the combined evaluation of documentation, code quality, test coverage, and security aspects of the project.
Risks
The project implements an Antisnipe functionality in LitlabGamesToken from Gotbit → which cannot be validated by Hacken since it has not been provided as part of the audit scope. This functionality is meant to authorize and control transactions happening during the token generation event (TGE) by the Gotbit team.
Both CyberTitansGame and CyberTitansTournament work in multiples of 8 players, but there is no code provided that checks and makes the groups. Instead, those player groups are imputed by the LitlabGames server off-chain and cannot be verified. This affects the functions createGame(), finalizeGame(), checkWallets(), startTournament(), finalizeTournament().
The flow of the project is not wholly on-chain (i.e. defined in smart contracts) since the project server holds a big part of it, and hence it's not completely verifiable.
The system is fully centralized, an owner can withdraw any available number of ERC20 tokens from the smart contracts by the use of the emergencyWithdraw() function.
The system is accepting arbitrary tokens in the CyberTitansGame and CyberTitansTournament contracts. If those tokens are a fee-on-transfer or reflection tokens the system will not work correctly.
After the project team responded to the issues, some of them were marked as Mitigated; those issues are not fixed, the project accepted and acknowledged those findings and took responsibility for their correctness.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2023-0183 | Invalid Calculations | fixed | Critical | |
| F-2023-0182 | Data Consistency | fixed | Critical | |
| F-2023-0181 | Data Consistency | fixed | Critical | |
| F-2023-0180 | Invalid Calculations | fixed | Critical | |
| F-2023-0179 | Invalid Calculations | fixed | Critical | |
| F-2023-0178 | Data Consistency | fixed | Critical | |
| F-2023-0200 | Data Consistency | mitigated | High | |
| F-2023-0199 | Non-Finalized Code | fixed | High | |
| F-2023-0198 | Requirements Violation | mitigated | High | |
| F-2023-0197 | Requirements Violation | mitigated | High |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/jgomes79/LitLabGames/→ |
| Commit | 1b7b59ccdb29c3d95ebdb9080819abbb707a93ba |
| Whitepaper | Provided→ |
| Requirements | Provided→ |
| Technical Requirements | Provided→ |