Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] Mushroom Finance | Mushroom Vaults V2 | Jun2024

Date:

Jul 5, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Mushroom Finance team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

Mushroom Vaults is a yield farming strategy that stakes tokens in LidoEth.

Document

NameSmart Contract Code Review and Security Analysis Report for Mushroom Finance
Audited ByOlesia Bilenka
Approved ByAtaberk Yavuzer
Websitehttps://mushroom.finance/→
Changelog20/06/2024 - Preliminary Report
10/07/2024  - Final Report
PlatformEthereum Mainnet
LanguageSolidity
TagsYield Farming
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for Mushroom Finance
    Audited By
    Olesia Bilenka
    Approved By
    Ataberk Yavuzer
    Changelog
    20/06/2024 - Preliminary Report
    10/07/2024  - Final Report
    Platform
    Ethereum Mainnet
    Language
    Solidity
    Tags
    Yield Farming

Audit Summary

12Total Findings
9Resolved
2Accepted
1Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Functional requirements are not provided.

  • Technical description is not provided.

Code quality

  • The code mostly follows Solidity style guide.

  • The development environment is configured.

Test coverage

Code coverage of the project is 9% (branch coverage).

  • Tests do not cover all the functionality.

System Overview

Mushroom Vaults is a yield farming strategy that stakes tokens in LidoEth. The core of the system consists of several contracts,

BaseStrategy is an abstract contract that contains the fundamental logic for yield farming strategies. It includes harvest and tend functionalities to manage the periodic harvesting and tending of the yield farming strategy. The contract features a robust permission system with roles for various actors, including keepers, vault managers, rewarders, governance, strategy managers, and emergency authorized personnel. Additionally, it has various configurations such as metadata, health check mechanisms, minimum and maximum report delays to the vault, emergency exit procedures, base fee oracle integration, credit thresholds, and force harvest triggers.

BaseStrategyInitializable is similar to BaseStrategy but includes clone functionality, allowing for the creation of identical strategy contracts. This facilitates easy deployment and scaling of the yield farming strategy.

Strategy is a contract that inherits from BaseStrategy and implements specific logic for yield farming with LidoEth. It handles investing by staking tokens in LidoEth, divesting by withdrawing tokens through the Curve exchange, and performing calculations for token withdrawals, profit, and loss. This ensures efficient and accurate yield management.

Privileged roles

Emergency Authorized (strategist, governance, vault guardian, vault management): Allowed to set emergency exit, update referral, invest, and rescue stuck ETH.

Authorized (strategist, governance): Allowed to set strategist, keeper, min report delay, max report delay, and metadata URI.

Strategist: Allowed to set rewards.

Governance: Allowed to sweep tokens.

Rewarder (strategist, governance): Allowed to set rewards address.

Keepers (keeper, strategist, governance, vault guardian, vault management): Allowed to call tend and harvest.

Vault Managers (vault management, governance): Allowed to set health check, credit threshold, force harvest trigger once, base fee oracle, max single trade, peg, report loss, don't invest variable, and slippage value.

Risks

Scope Definition and Security Guarantees: The audit does not cover all code in the repository. Contracts outside the audit scope may introduce vulnerabilities, potentially impacting the overall security due to the interconnected nature of smart contracts. (Vault functionality)

Dependency on External Logic for Implemented Logic: The implemented Strategy contract logic highly depends on external contracts not covered by the audit. This reliance introduces risks if these external contracts are compromised or contain vulnerabilities, affecting the audited project's integrity.

Insufficient Permissioning and Documentation: Inadequate permissions and under-documentation heighten the risk of unauthorized access and actions, complicating issue resolution and increasing the potential for security breaches.

Absence of Time-lock Mechanisms for Critical Operations: Without time-locks on critical operations, there is no buffer to review or revert potentially harmful actions, increasing the risk of rapid exploitation and irreversible changes.

Low Test coverage: Code coverage of the project is 9% (branch coverage). Tests do not cover all the main functionality.

Findings

F-2024-3911Incorrect Calculation in prepareReturn Function Leading to Excessive and Failed Withdrawals
Status
fixed
Severity

Medium
F-2024-3924Inconsistent Initialization in BaseStrategyInitializable
Status
fixed
Severity

Low
F-2024-3916Pre-Execution Checks Leading to Non-Compliance in harvest and tend Functions
Status
mitigated
Severity

Low
F-2024-3994Potential Risk of Ignoring dontInvest Restriction in invest Function
Status
accepted
Severity

Observation
F-2024-3921Unchecked Transfer Results Leading to Strategy Migration Inconsistency
Status
fixed
Severity

Observation
F-2024-3920Violation of Checks-Effects-Interactions Pattern
Status
fixed
Severity

Observation
F-2024-3919Redundant doHealthCheck Setting in harvest Function When healthCheck is Zero Address
Status
fixed
Severity

Observation
F-2024-3915Lack of Balance Check in liquidatePosition Function
Status
accepted
Severity

Observation
F-2024-3913Redundant Variable Declaration
Status
fixed
Severity

Observation
F-2024-3912Redundant Initializations to Default Values
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-3911Incorrect Calculation in prepareReturn Function Leading to Excessive and Failed Withdrawals
fixed

Medium
F-2024-3924Inconsistent Initialization in BaseStrategyInitializable
fixed

Low
F-2024-3916Pre-Execution Checks Leading to Non-Compliance in harvest and tend Functions
mitigated

Low
F-2024-3994Potential Risk of Ignoring dontInvest Restriction in invest Function
accepted

Observation
F-2024-3921Unchecked Transfer Results Leading to Strategy Migration Inconsistency
fixed

Observation
F-2024-3920Violation of Checks-Effects-Interactions Pattern
fixed

Observation
F-2024-3919Redundant doHealthCheck Setting in harvest Function When healthCheck is Zero Address
fixed

Observation
F-2024-3915Lack of Balance Check in liquidatePosition Function
accepted

Observation
F-2024-3913Redundant Variable Declaration
fixed

Observation
F-2024-3912Redundant Initializations to Default Values
fixed

Observation
1-10 of 12 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Severity Definitions

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Scope Details

Repositoryhttps://github.com/mushroom-finance/mushroom-vaults-v2/tree/main→
Commit737bc3e939d61be13cdf3262643161cdd34b203e
WhitepaperNot provided

Contracts in Scope

src
BaseStrategy.sol - src › BaseStrategy.sol
strategies
lido
Strategy.sol - src › strategies › lido › Strategy.sol
interfaces
curve
IStableSwapSTETH.sol - src › interfaces › curve › IStableSwapSTETH.sol
IWETH.sol - src › interfaces › IWETH.sol
IRegistry.sol - src › interfaces › IRegistry.sol
ILido.sol - src › interfaces › ILido.sol

Disclaimer