Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] LitLab Games | GameFI | Mar2023

Date:

May 1, 2023

Table of Content

→Introduction
→Audit Summary
→Document Information
→System Overview
→Executive Summary
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the LitLab Games team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

LitLab Games generates sustainable environments and new monetization models through LITT adoption in all of our published games, providing blockchain tools with a full web 2.0 experience.

titlecontent
PlatformEVM
LanguageSolidity
TagsERC20; Staking; Vesting; Gaming
Timeline14/03/2023 - 05/05/2023
Methodologyhttps://hackenio.cc/sc_methodology→

    Review Scope

    Repositoryhttps://github.com/jgomes79/LitLabGames→
    Commit1b7b59ccdb29c3d95ebdb9080819abbb707a93ba

    Audit Summary

    Total7.2/10
    Security Score

    10/10

    Test Coverage

    49.16%

    Code Quality Score

    8/10

    Documentation Quality Score

    7/10

    64Total Findings
    54Resolved
    0Accepted
    10Mitigated

    The system users should acknowledge all the risks summed up in the risks section of the report

    Document Information

    This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.

    The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.

    Document

    NameSmart Contract Code Review and Security Analysis Report for LitLab Games
    Audited ByHacken
    Websitehttps://litlabgames.com→
    Changelog21/03/2023 - Initial Review
    13/04/2023 - Second Review
    05/05/2023 - Third Review
    • Document

      Name
      Smart Contract Code Review and Security Analysis Report for LitLab Games
      Audited By
      Hacken
      Changelog
      21/03/2023 - Initial Review
      13/04/2023 - Second Review
      05/05/2023 - Third Review

    System Overview

    LitLab Games is a mixed-purpose system with the following contracts:

    • LitlabGamesToken — ERC-20 permit token that mints all initial supply to a deployer. Allows burning mechanisms and implements an antisnipe functionality from Gotbit →. It has the following attributes:

      • Name: LitlabToken

      • Symbol: LITT

      • Decimals: 18

      • Total supply: 3b tokens.

    • LitlabGamesToken — an interface for a burnable ERC20 token.

    • Ownable – an abstract smart contract that implements the possibility of ownership.

    • LitlabPreStakingBox – a staking smart contract, which is used to issue an initial token offer to a limited number of users. Staking participants can only be added by the owner. Also, only the owner assigns the amount of the reward received as a result of staking.

    • LITTAdvisorsTeam – a vesting smart contract which is used to distribute tokens for advisors and the team. The smart contract ses a linear distribution of tokens. A team needs to verify three different wallets in order to withdraw their rewards.

    • LITTVestingContract – a vesting smart contract which is used to distribute the supply of tokens in accordance with the whitepaper and distribution schedule.

    • CyberTitansGame – a smart contract used for creating and managing games. The game in this case is an abstract thing, it stores a list of players and winners. Winners are chosen outside the blockchain. The contract calculates and sends the rewards for the winners.

    • CyberTitansTournament – a smart contract used for creating and managing tournaments. The tournaments in this case is an abstract thing, it stores a list of participants, calculate rewards according to the amount of players. Anyone can join the tournament, winners are chosen outside the blockchain.

    • LitlabContext – an instance of simple ERC2771Context smart contract.

    • LitlabForwarder – a forwarder smart contract which will be used for metatransactions.

    Privileged roles

    • The owner of the CyberTitansGame contract can change addresses of manager role, address for fee collecting, native game ERC20 token address. The owner can change game winners, fees percentage, withdrawal delay, maximum bet amount, pause/unpause smart contract and withdraw any amount of tokens from the contract.

    • The manager of the CyberTitansGame can create and end games.

    • The owner of the CyberTitansTournament contract can change addresses of manager role, address for fee collecting, native game ERC20 token address. The owner can change reward matrix, fees percentage, pause/unpause smart contract and withdraw any amount of tokens from the contract.

    • The manager of the CyberTitansGame can start and end tournaments.

    • The owner of the LitlabGamesToken can disable antisnipe system, which is not in the scope.

    • The owner of the LitlabPreStakingBox can add new investors to staking. The owner can withdraw any amount of tokens from the contract.

    • The owner of LITTAdvisorsTeam can set start time of vesting, add and remove advisors, set advisors’ rewards, set approval wallets for team rewards withdrawing and change address of team wallet. The owner can withdraw any amount of tokens from the contract.

    • The owner of LITTVestingContract can set the start time of vesting, change the company wallet. The owner can withdraw any amount of tokens from the contract.

    Recommendations

    • Owner private keys should be ⅗ multi-sig.

    • Test coverage should be updated.

    Executive Summary

    Documentation quality

    The total Documentation quality score is 7 out of 10.

    • Overall system requirements are provided.

    • No run instructions.

    • Technical specification is provided.

    • NatSpec is not fully provided.

    Code quality

    The total Code quality score is 8 out of 10.

    • Development environment is not configured.

    Test coverage

    Code coverage of the project is 49.16% (branch coverage).

    • Test coverage is insufficient.

    Security score

    Upon auditing, the code was found to contain 6 critical, 17 high, 20 medium, and 20 low severity issues. Out of these, 53 issues have been addressed and resolved, leading to a Security score of 10 out of 10.

    All identified issues are detailed in the “Findings” section of this report.

    Summary

    The comprehensive audit of the customer's smart contract yields an overall score of 7.2. This score reflects the combined evaluation of documentation, code quality, test coverage, and security aspects of the project.

    Risks

    The project implements an Antisnipe functionality in LitlabGamesToken from Gotbit → which cannot be validated by Hacken since it has not been provided as part of the audit scope. This functionality is meant to authorize and control transactions happening during the token generation event (TGE) by the Gotbit team.

    Both CyberTitansGame and CyberTitansTournament work in multiples of 8 players, but there is no code provided that checks and makes the groups. Instead, those player groups are imputed by the LitlabGames server off-chain and cannot be verified. This affects the functions createGame(), finalizeGame(), checkWallets(), startTournament(), finalizeTournament().

    The flow of the project is not wholly on-chain (i.e. defined in smart contracts) since the project server holds a big part of it, and hence it's not completely verifiable.

    The system is fully centralized, an owner can withdraw any available number of ERC20 tokens from the smart contracts by the use of the emergencyWithdraw() function.

    The system is accepting arbitrary tokens in the CyberTitansGame and CyberTitansTournament contracts. If those tokens are a fee-on-transfer or reflection tokens the system will not work correctly.

    After the project team responded to the issues, some of them were marked as Mitigated; those issues are not fixed, the project accepted and acknowledged those findings and took responsibility for their correctness.

    Findings

    F-2023-0183 Invalid Calculations
    Status
    fixed
    Severity

    Critical
    F-2023-0182 Data Consistency
    Status
    fixed
    Severity

    Critical
    F-2023-0181Data Consistency
    Status
    fixed
    Severity

    Critical
    F-2023-0180Invalid Calculations
    Status
    fixed
    Severity

    Critical
    F-2023-0179Invalid Calculations
    Status
    fixed
    Severity

    Critical
    F-2023-0178Data Consistency
    Status
    fixed
    Severity

    Critical
    F-2023-0200Data Consistency
    Status
    mitigated
    Severity

    High
    F-2023-0199 Non-Finalized Code
    Status
    fixed
    Severity

    High
    F-2023-0198Requirements Violation
    Status
    mitigated
    Severity

    High
    F-2023-0197Requirements Violation
    Status
    mitigated
    Severity

    High
    Code
    ―
    Title
    Status
    Severity
    F-2023-0183 Invalid Calculations
    fixed

    Critical
    F-2023-0182 Data Consistency
    fixed

    Critical
    F-2023-0181Data Consistency
    fixed

    Critical
    F-2023-0180Invalid Calculations
    fixed

    Critical
    F-2023-0179Invalid Calculations
    fixed

    Critical
    F-2023-0178Data Consistency
    fixed

    Critical
    F-2023-0200Data Consistency
    mitigated

    High
    F-2023-0199 Non-Finalized Code
    fixed

    High
    F-2023-0198Requirements Violation
    mitigated

    High
    F-2023-0197Requirements Violation
    mitigated

    High
    1-10 of 64 findings

    Identify vulnerabilities in your smart contracts.

    Appendix 1. Severity Definitions

    When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

    Reference on how risk scoring is done is available through the repository in our Github organization:

    Severity

    Description

    Critical
    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    High
    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Medium
    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Low
    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
    • Severity

      Critical

      Description

      Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

      Severity

      High

      Description

      High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

      Severity

      Medium

      Description

      Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

      Severity

      Low

      Description

      Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

    Appendix 2. Scope

    The scope of the project includes the following smart contracts from the provided repository:

    Scope Details

    Repositoryhttps://github.com/jgomes79/LitLabGames/→
    Commit1b7b59ccdb29c3d95ebdb9080819abbb707a93ba
    WhitepaperProvided→
    RequirementsProvided→
    Technical RequirementsProvided→

    Contracts in Scope

    contracts
    game
    CyberTitansGame.sol - contracts › game › CyberTitansGame.sol
    CyberTitansTournament.sol - contracts › game › CyberTitansTournament.sol
    metatx
    LitlabContext.sol - contracts › metatx › LitlabContext.sol
    LitlabForwarder.sol - contracts › metatx › LitlabForwarder.sol
    staking
    LitlabPreStakingBox.sol - contracts › staking › LitlabPreStakingBox.sol
    token
    ILitlabGamesToken.sol - contracts › token › ILitlabGamesToken.sol
    LitlabGamesToken.sol - contracts › token › LitlabGamesToken.sol
    utils
    Ownable.sol - contracts › utils › Ownable.sol
    vesting
    LITTAdvisorsTeam.sol - contracts › vesting › LITTAdvisorsTeam.sol
    LITTVestingContract.sol - contracts › vesting › LITTVestingContract.sol

    Disclaimer