Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] NodeTerminal | Lumia-Contracts | Aug2024

Date:

Aug 20, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the NodeTerminal team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

Node Terminal created a  Lumia Node sale contract, responsible for handling Lumia nodes sale using Node Terminal platform. It collects payments in ERC-20 token (in particular USDT) and increases number of nodes assigned to the account. This data will be used for future NFT airdrop.

Document

NameSmart Contract Code Review and Security Analysis Report for NodeTerminal
Audited ByDavid Camps Novi
Approved ByPrzemyslaw Swiatowiec
Websitehttp://nodeterminal.com/→
Changelog16/08/2024 - Preliminary Report; 20/08/2024 - Final Report
PlatformPolygon, Arbitrum
LanguageSolidity
TagsAirdrop
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for NodeTerminal
    Audited By
    David Camps Novi
    Approved By
    Przemyslaw Swiatowiec
    Changelog
    16/08/2024 - Preliminary Report; 20/08/2024 - Final Report
    Platform
    Polygon, Arbitrum
    Language
    Solidity
    Tags
    Airdrop

Audit Summary

3Total Findings
3Resolved
0Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Functional requirements are provided.

  • Technical description is provided.

Code quality

  • Best practices are followed

  • The development environment is configured.

Test coverage

Code coverage of the project is 97.5% (branch coverage).

  • Deployment and basic user interactions are covered with tests.

System Overview

The audited Node Terminal project consists of a single Lumia Node sale contract, responsible for handling Lumia nodes sale using Node Terminal platform.

  • LumiaNodeNT.sol - Collects payments in ERC-20 token (in particular USDT) and increases number of nodes assigned to the account. This data will be used for future NFT airdrop.

Privileged roles

  • DEFAULT_ADMIN_ROLE - can set the number of nodes a new account owns.

  • MASTER_ROLE - sets the state of the sale as active or inactive, which controls the cals to buy nodes.

  • ADMIN_ROLE - can increase the number of nodes an account owns.

Risks

The project utilizes Solidity version 0.8.24, which includes the introduction of the PUSH0 (0x5f) opcode. This opcode is currently supported on the Ethereum mainnet but may not be universally supported across other blockchain networks. Consequently, deploying the contract on chains other than the Ethereum mainnet, such as certain Layer 2 (L2) chains or alternative networks, might lead to compatibility issues or execution errors due to the lack of support for the PUSH0 opcode. In scenarios where deployment on various chains is anticipated, selecting an appropriate Ethereum Virtual Machine (EVM) version that is widely supported across these networks is crucial to avoid potential operational disruptions or deployment failures.

The ADMIN_ROLE can increase the number of nodes an account for free, resulting in a potential disadvantage for buyers.

The MASTER_ROLE can set the sale status to active or inactive at will, controlling when users are allowed to purchase nodes.

The DEFAULT_ADMIN_ROLE can override the balance of nodes of a user, even decreasing the number of nodes they already purchased.

Findings

F-2024-5400Missing Zero Check For ntCommissionsInBp Parameter
Status
fixed
Severity

Observation
F-2024-5392Missing Event for Key Value Update
Status
fixed
Severity

Observation
F-2024-5391Floating Pragma
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-5400Missing Zero Check For ntCommissionsInBp Parameter
fixed

Observation
F-2024-5392Missing Event for Key Value Update
fixed

Observation
F-2024-5391Floating Pragma
fixed

Observation
1-3 of 3 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Severity Definitions

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Scope Details

Repositoryhttps://github.com/Node-Terminal/node-terminal-contracts→
Commitc2998b2
Whitepaperhttps://nodeterminal.gitbook.io/nodeterminal→
RequirementsREADME.md, NatSpec
Technical RequirementsREADME.md

Contracts in Scope

contracts
providers
lumia
NodesSale.sol - contracts › providers › lumia › NodesSale.sol

Disclaimer