Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] MotoBloq | ERC721 | Aug2023

Date:

Aug 18, 2023

Table of Content

→Introduction
→Audit Summary
→Document Information
→System Overview
→Executive Summary
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the MotoBloq team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

MotoBloq is a car collecting game that utilizes blockchain technology (think Bitcoin technology) to collect and title (track ownership) of digital (virtual) cars. The goal of MotoBloq is for each user to own their dream car and build their dream garage.

titlecontent
PlatformEthereum
LanguageSolidity
TagsERC721
Timeline10/08/2023 - 17/08/2023
Methodologyhttps://hackenio.cc/sc_methodology→

    Review Scope

    Repositoryhttps://github.com/MotoBloq/motobloq-sm-external→
    Commit69d96e43cdf0f84ea1bd77aa4b6a7334badea77e

    Audit Summary

    Total10/10
    Security Score

    10/10

    Test Coverage

    100%

    Code Quality Score

    10/10

    Documentation Quality Score

    10/10

    9Total Findings
    9Resolved
    0Accepted
    0Mitigated

    The system users should acknowledge all the risks summed up in the risks section of the report

    Document Information

    This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.

    The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.

    Document

    NameSmart Contract Code Review and Security Analysis Report for MotoBloq
    Audited ByHacken
    Websitehttps://motobloq.com/→
    Changelog11/04/2023 – Initial Review
    18/05/2023 – Second Review
    29/05/2023 - Third Review
    25/07/2023 - Fourth Review
    17/08/2023 - Fifth Review
    • Document

      Name
      Smart Contract Code Review and Security Analysis Report for MotoBloq
      Audited By
      Hacken
      Changelog
      11/04/2023 – Initial Review
      18/05/2023 – Second Review
      29/05/2023 - Third Review
      25/07/2023 - Fourth Review
      17/08/2023 - Fifth Review

    System Overview

    MotobloqToken is a mixed-purpose system with the following contracts:

    • MotobloqToken - A custom ERC-721 token contract with royalty support that inherits from ERC721MinterBurnerPauser and implements the ERC2981 standard. It has the following attributes: Name: MotobloqToken. Symbol: MBT. The contract allows minting, burning, and pausing token transfers, and it also supports royalty management for the tokens.

    • ERC721MinterBurnerPauser - A customizable ERC-721 token contract with minting, burning, and pausing functionalities. It inherits from Context, AccessControl, ERC721Burnable, ERC721Pausable, and ERC721URIStorage. The contract utilizes role-based access control for minting and pausing functions, and supports auto-generated token URIs based on a base URI and token IDs.

    Privileged roles

    • DEFAULTADMINROLE - Has the power to grant and revoke roles (MINTERROLE and PAUSERROLE) to other accounts and change the token URI.

    • MINTER_ROLE - Allows accounts with this role to mint new tokens using the mint() function.

    • PAUSER_ROLE - Allows accounts with this role to pause or unpause all token transfers using the pause() and unpause() functions.

    Executive Summary

    Documentation quality

    The total Documentation quality score is 10 out of 10.

    • Functional requirements are provided.

    • Technical description is provided.

    • NatSpec is provided.

    Code quality

    The total Code quality score is 10 out of 10.

    • The development environment is configured.

    Test coverage

    Code coverage of the project is 100% (branch coverage).

    • Error in the plugin solidity-coverage: “AssertionError: expected 'MotoBloq' to equal 'MotobloqToken’”.

    Security score

    Upon auditing, the code was found to contain 0 critical, 2 high, 3 medium, and 4 low severity issues. Out of these, 9 issues have been addressed and resolved, leading to a security score of 10 out of 10.

    All identified issues are detailed in the “Findings” section of this report.

    Summary

    The comprehensive audit of the customer's smart contract yields an overall score of 10. This score reflects the combined evaluation of documentation, code quality, test coverage, and security aspects of the project.

    Risks

    The relayers are part of the Motobloq cluster, which is responsible for facilitating token transfers between the Motobloq blockchain and Ethereum Mainnet; those are not included in this audit and cannot be assessed for their correctness.

    The token URI can be changed by the DEFAULT_ADMIN_ROLE, all the functionalities in the protocol, including the functionality to change the token URI are centralized. Therefore, for the protocol to operate correctly, the central authority controlling these functions must operate effectively.

    Error in the plugin solidity-coverage: “AssertionError: expected 'MotoBloq' to equal 'MotobloqToken’”

    Findings

    F-2023-158Undocumented Functionality
    Status
    fixed
    Severity

    High
    F-2023-1585Best Practice Violation
    Status
    fixed
    Severity

    High
    F-2023-158Unscalable Functionality
    Status
    fixed
    Severity

    Medium
    F-2023-158Best Practice Violation
    Status
    fixed
    Severity

    Medium
    F-2023-158Inconsistent Data
    Status
    fixed
    Severity

    Medium
    F-2023-1593 Floating Pragma
    Status
    fixed
    Severity

    Low
    F-2023-159Variable Shadowing
    Status
    fixed
    Severity

    Low
    F-2023-159Functions That Can Be Declared External
    Status
    fixed
    Severity

    Low
    F-2023-159Redundant Import And Inheritance
    Status
    fixed
    Severity

    Low
    Code
    ―
    Title
    Status
    Severity
    F-2023-158Undocumented Functionality
    fixed

    High
    F-2023-1585Best Practice Violation
    fixed

    High
    F-2023-158Unscalable Functionality
    fixed

    Medium
    F-2023-158Best Practice Violation
    fixed

    Medium
    F-2023-158Inconsistent Data
    fixed

    Medium
    F-2023-1593 Floating Pragma
    fixed

    Low
    F-2023-159Variable Shadowing
    fixed

    Low
    F-2023-159Functions That Can Be Declared External
    fixed

    Low
    F-2023-159Redundant Import And Inheritance
    fixed

    Low
    1-9 of 9 findings

    Identify vulnerabilities in your smart contracts.

    Appendix 1. Severity Definitions

    When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

    Reference on how risk scoring is done is available through the repository in our Github organization:

    Severity

    Description

    Critical
    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    High
    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Medium
    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Low
    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
    • Severity

      Critical

      Description

      Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

      Severity

      High

      Description

      High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

      Severity

      Medium

      Description

      Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

      Severity

      Low

      Description

      Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

    Appendix 2. Scope

    The scope of the project includes the following smart contracts from the provided repository:

    Scope Details

    Repositoryhttps://github.com/MotoBloq/motobloq-sm-external→
    Commit69d96e43cdf0f84ea1bd77aa4b6a7334badea77e
    WhitepaperNot provided
    RequirementsProvided
    Technical RequirementsProvided

    Contracts in Scope

    contracts
    ERC721MinterBurnerPauser.sol - contracts › ERC721MinterBurnerPauser.sol
    MotobloqToken.sol - contracts › MotobloqToken.sol

    Disclaimer