Introduction
We express our gratitude to the Mushroom Finance team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
Mushroom Vaults is a yield farming strategy that stakes tokens in LidoEth.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for Mushroom Finance |
| Audited By | Olesia Bilenka |
| Approved By | Ataberk Yavuzer |
| Website | https://mushroom.finance/→ |
| Changelog | 20/06/2024 - Preliminary Report |
| 10/07/2024 - Final Report | |
| Platform | Ethereum Mainnet |
| Language | Solidity |
| Tags | Yield Farming |
| Methodology | https://hackenio.cc/sc_methodology→ |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for Mushroom Finance
- Audited By
- Olesia Bilenka
- Approved By
- Ataberk Yavuzer
- Website
- https://mushroom.finance/→
- Changelog
- 20/06/2024 - Preliminary Report
- 10/07/2024 - Final Report
- Platform
- Ethereum Mainnet
- Language
- Solidity
- Tags
- Yield Farming
- Methodology
- https://hackenio.cc/sc_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/mushroom-finance/mushroom-vaults-v2/tree/main→ |
| Commit | 737bc3e |
Review Scope
- Commit
- 737bc3e
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
Functional requirements are not provided.
Technical description is not provided.
Code quality
The code mostly follows Solidity style guide.
The development environment is configured.
Test coverage
Code coverage of the project is 9% (branch coverage).
Tests do not cover all the functionality.
System Overview
Mushroom Vaults is a yield farming strategy that stakes tokens in LidoEth. The core of the system consists of several contracts,
BaseStrategy is an abstract contract that contains the fundamental logic for yield farming strategies. It includes harvest and tend functionalities to manage the periodic harvesting and tending of the yield farming strategy. The contract features a robust permission system with roles for various actors, including keepers, vault managers, rewarders, governance, strategy managers, and emergency authorized personnel. Additionally, it has various configurations such as metadata, health check mechanisms, minimum and maximum report delays to the vault, emergency exit procedures, base fee oracle integration, credit thresholds, and force harvest triggers.
BaseStrategyInitializable is similar to BaseStrategy but includes clone functionality, allowing for the creation of identical strategy contracts. This facilitates easy deployment and scaling of the yield farming strategy.
Strategy is a contract that inherits from BaseStrategy and implements specific logic for yield farming with LidoEth. It handles investing by staking tokens in LidoEth, divesting by withdrawing tokens through the Curve exchange, and performing calculations for token withdrawals, profit, and loss. This ensures efficient and accurate yield management.
Privileged roles
Emergency Authorized (strategist, governance, vault guardian, vault management): Allowed to set emergency exit, update referral, invest, and rescue stuck ETH.
Authorized (strategist, governance): Allowed to set strategist, keeper, min report delay, max report delay, and metadata URI.
Strategist: Allowed to set rewards.
Governance: Allowed to sweep tokens.
Rewarder (strategist, governance): Allowed to set rewards address.
Keepers (keeper, strategist, governance, vault guardian, vault management): Allowed to call tend and harvest.
Vault Managers (vault management, governance): Allowed to set health check, credit threshold, force harvest trigger once, base fee oracle, max single trade, peg, report loss, don't invest variable, and slippage value.
Risks
Scope Definition and Security Guarantees: The audit does not cover all code in the repository. Contracts outside the audit scope may introduce vulnerabilities, potentially impacting the overall security due to the interconnected nature of smart contracts. (Vault functionality)
Dependency on External Logic for Implemented Logic: The implemented Strategy contract logic highly depends on external contracts not covered by the audit. This reliance introduces risks if these external contracts are compromised or contain vulnerabilities, affecting the audited project's integrity.
Insufficient Permissioning and Documentation: Inadequate permissions and under-documentation heighten the risk of unauthorized access and actions, complicating issue resolution and increasing the potential for security breaches.
Absence of Time-lock Mechanisms for Critical Operations: Without time-locks on critical operations, there is no buffer to review or revert potentially harmful actions, increasing the risk of rapid exploitation and irreversible changes.
Low Test coverage: Code coverage of the project is 9% (branch coverage). Tests do not cover all the main functionality.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-3911 | Incorrect Calculation in prepareReturn Function Leading to Excessive and Failed Withdrawals | fixed | Medium | |
| F-2024-3924 | Inconsistent Initialization in BaseStrategyInitializable | fixed | Low | |
| F-2024-3916 | Pre-Execution Checks Leading to Non-Compliance in harvest and tend Functions | mitigated | Low | |
| F-2024-3994 | Potential Risk of Ignoring dontInvest Restriction in invest Function | accepted | Observation | |
| F-2024-3921 | Unchecked Transfer Results Leading to Strategy Migration Inconsistency | fixed | Observation | |
| F-2024-3920 | Violation of Checks-Effects-Interactions Pattern | fixed | Observation | |
| F-2024-3919 | Redundant doHealthCheck Setting in harvest Function When healthCheck is Zero Address | fixed | Observation | |
| F-2024-3915 | Lack of Balance Check in liquidatePosition Function | accepted | Observation | |
| F-2024-3913 | Redundant Variable Declaration | fixed | Observation | |
| F-2024-3912 | Redundant Initializations to Default Values | fixed | Observation |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/mushroom-finance/mushroom-vaults-v2/tree/main→ |
| Commit | 737bc3e939d61be13cdf3262643161cdd34b203e |
| Whitepaper | Not provided |
Scope Details
- Commit
- 737bc3e939d61be13cdf3262643161cdd34b203e
- Whitepaper
- Not provided