Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] RedFox | NFT sale | May2022

Date:

Jun 13, 2022

Table of Content

→Introduction
→Audit Summary
→Document Information
→System Overview
→Executive Summary
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the RedFox team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

RedFox's vision is to be the global leader in immersive metaverse experiences focused on retail, media, gaming & rewards. RFOX token is the multichain digital asset that fuels the RFOX metaverse ecosystem and its immersive technology.

titlecontent
PlatformEVM
LanguageSolidity
TagsERC721 token, ERC1155 token, Token sale
Timeline16/05/2022 - 14/06/2022
Methodologyhttps://hackenio.cc/sc_methodology→

    Review Scope

    Repositoryhttps://github.com/RFL-NFTPlatform/nft-factory→
    Commit731ccbdb6df349432a57f997383d51860c82a4b2

    Audit Summary

    Total9.3/10
    Security Score

    10/10

    Test Coverage

    10/10

    Code Quality Score

    7/10

    Documentation Quality Score

    6/10

    4Total Findings
    3Resolved
    0Accepted
    1Mitigated

    The system users should acknowledge all the risks summed up in the risks section of the report

    Document Information

    This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.

    The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.

    Document

    NameSmart Contract Code Review and Security Analysis Report for RedFox
    Audited ByHacken
    Websitehttps://www.rfox.com/→
    Changelog24/05/2022 - Initial Review
    14/06/2022 - Second Review
    • Document

      Name
      Smart Contract Code Review and Security Analysis Report for RedFox
      Audited By
      Hacken
      Changelog
      24/05/2022 - Initial Review
      14/06/2022 - Second Review

    System Overview

    Red Fox is an ERC721 and ERC1155 NFT system with the following contracts:

    • RFOXFactoryStandard - factory contract to create new RFOXNFTStandart and store their addresses.

    • RFOXFactoryStandardBotPrevention - factory contract to create new RFOXNFTStandartBotPrevention and store their addresses.

    • RFOXFactoryWhitelist - factory contract to create new RFOXFactoryWhiteList and store their addresses.

    • RFOXFactoryWhitelistBotPrevention - factory contract to create new RFOXFactoryWhiteListBotPrevention and store their addresses.

    • BaseRFOXNFT - base contract with functionality to work with the other project`s contracts.

    • BaseRFOXNFTPresale \- base contract for presale and whitelist mechanism.

    • RFOXNFTPresale - contract for implementation of the presale of NFT.

    • RFOXNFTSale - contract with public NFT selling function.

    • RFOXNFTSignaturePresale - contract with a signature presale function.

    • RFOXNFTSignatureSale - contract with the extension for the base contract, adding the signature mechanism.

    • ParamStructs - contract with parameters for another project`s contract.

    • RFOXNFTStandard — contract with the initializing function of the standard RFOX NFT.

    • RFOXNFTStandardBotPrevention — contract with the initializing function of the standard RFOX NFT with bot prevention.

    • RFOXNFTWhitelist — contract with the initializing function of the standard RFOX NFT with a presale for whitelist.

    • RFOXNFTWhitelistBotPrevention — contract with the initializing function of the standard RFOX NFT with a presale for whitelist and bot prevention.

    • RFOXFactoryStandard1155 - factory contract to create new RFOXNFTStandart1155 and store their addresses.

    • RFOXFactoryStandardBotPrevention1155 - factory contract to create new RFOXNFTStandartBotPrevention1155 and store their addresses.

    • RFOXFactoryWhitelist1155 - factory contract to create new RFOXFactoryWhiteList1155 and store their addresses.

    • RFOXFactoryWhitelistBotPrevention1155 - factory contract to create new RFOXFactoryWhiteListBotPrevention1155 and store their addresses.

    • BaseRFOXNFT1155 - base contract with functionality to work with the other project`s ERC1155 contracts.

    • BaseRFOXNFTPresale1155 - base contract for presale and whitelist mechanism for ERC1155 contracts.

    • RFOXNFTPresale1155 - contract for implementation of the presale of ERC1155 tokens.

    • RFOXNFTSale1155 - contract with public ERC1155 tokens selling function.

    • RFOXNFTSignaturePresale1155 - contract with a signature presale function.

    • RFOXNFTSignatureSale1155 - contract with the extension for the base contract, adding the signature mechanism.

    • ParamStructs1155 - contract with parameters for another project`s ERC1155 contracts.

    • RFOXNFTStandard1155 — contract with the initializing function of the standard RFOX NFT and a function for updating token settings.

    • RFOXNFTStandardBotPrevention1155 — contract with the initializing function of the standard RFOX NFT with bot prevention and a function for updating token settings.

    • RFOXNFTWhitelist1155 — contract with the initializing function of the standard RFOX NFT with a presale for whitelist and a function for updating token settings.

    • RFOXNFTWhitelistBotPrevention1155 — contract with the initializing function of the standard RFOX NFT with a presale for whitelist and bot prevention and a function for updating token settings.

    • IRFOXFactory - interface for factory contracts.

    Privileged roles

    • The Owner - can mint tokens, withdraw funds, update token`s data and price, call createNFT function in factory contracts, set base URI and maximum number of tokens per transaction, pause and unpause transactions, change authorized signer address, activate and deactivate whitelist feature and update Merkle root.

    Executive Summary

    Documentation quality

    The total Documentation quality score is 6 out of 10.

    • Superficial functional requirements provided.

    • Technical documentation is available in code.

    • Ttechnical requirements not provided

    Code quality

    The total Code quality score is 7 out of 10.

    • Unit tests were provided.

    • Code violates the order of functions and maximum line length defined in the style guide.

    Architecture quality

    The Architecture quality score is 10 out of 10.

    • Code use best practices.

    Security score

    Upon auditing, the code was found to contain 0 critical, 2 high, 1 medium, and 1 low severity issues. Out of these, 3 issues have been addressed and resolved, leading to a Security score of 10 out of 10.

    All identified issues are detailed in the “Findings” section of this report.

    Summary

    The comprehensive audit of the customer's smart contract yields an overall score of 9.3. This score reflects the combined evaluation of documentation, code quality, architecture quality, and security aspects of the project.

    Findings

    F-2022-1900Highly permissive owner access
    Status
    fixed
    Severity

    High
    F-2022-1899Owner can stop the project`s transactions.
    Status
    fixed
    Severity

    High
    F-2022-1901Multisig wallets will be rejected
    Status
    mitigated
    Severity

    Medium
    F-2022-1902Floating pragma
    Status
    fixed
    Severity

    Low
    Code
    ―
    Title
    Status
    Severity
    F-2022-1900Highly permissive owner access
    fixed

    High
    F-2022-1899Owner can stop the project`s transactions.
    fixed

    High
    F-2022-1901Multisig wallets will be rejected
    mitigated

    Medium
    F-2022-1902Floating pragma
    fixed

    Low
    1-4 of 4 findings

    Identify vulnerabilities in your smart contracts.

    Appendix 1. Severity Definitions

    When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

    Reference on how risk scoring is done is available through the repository in our Github organization:

    Severity

    Description

    Critical
    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    High
    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Medium
    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Low
    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
    • Severity

      Critical

      Description

      Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

      Severity

      High

      Description

      High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

      Severity

      Medium

      Description

      Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

      Severity

      Low

      Description

      Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

    Appendix 2. Scope

    The scope of the project includes the following smart contracts from the provided repository:

    Scope Details

    Repositoryhttps://github.com/RFL-NFTPlatform/nft-factory→
    Commit731ccbdb6df349432a57f997383d51860c82a4b2
    WhitepaperNot provided
    RequirementsProvided
    Technical RequirementsNot provided

    Contracts in Scope

    contracts
    erc1155
    factory
    RFOXFactoryStandard1155.sol - contracts › erc1155 › factory › RFOXFactoryStandard1155.sol
    RFOXFactoryStandardBotPrevention1155.sol - contracts › erc1155 › factory › RFOXFactoryStandardBotPrevention1155.sol
    RFOXFactoryWhitelist.sol - contracts › erc1155 › factory › RFOXFactoryWhitelist.sol
    RFOXFactoryWhitelistBotPrevention1155.sol - contracts › erc1155 › factory › RFOXFactoryWhitelistBotPrevention1155.sol
    lib
    base
    BaseRFOXNFT1155.sol - contracts › erc1155 › lib › base › BaseRFOXNFT1155.sol
    BaseRFOXNFTPresale1155.sol - contracts › erc1155 › lib › base › BaseRFOXNFTPresale1155.sol
    RFOXNFTPresale1155.sol - contracts › erc1155 › lib › RFOXNFTPresale1155.sol
    RFOXNFTSale1155.sol - contracts › erc1155 › lib › RFOXNFTSale1155.sol
    RFOXNFTSignaturePresale1155.sol - contracts › erc1155 › lib › RFOXNFTSignaturePresale1155.sol
    RFOXNFTSignatureSale1155.sol - contracts › erc1155 › lib › RFOXNFTSignatureSale1155.sol
    RFOXNFTStandard1155.sol - contracts › erc1155 › RFOXNFTStandard1155.sol
    RFOXNFTStandardBotPrevention1155.sol - contracts › erc1155 › RFOXNFTStandardBotPrevention1155.sol
    RFOXNFTWhitelist1155.sol - contracts › erc1155 › RFOXNFTWhitelist1155.sol
    RFOXNFTWhitelistBotPrevention1155.sol - contracts › erc1155 › RFOXNFTWhitelistBotPrevention1155.sol
    structs
    ParamStructs1155.sol - contracts › erc1155 › structs › ParamStructs1155.sol
    TokenStructs.sol - contracts › erc1155 › structs › TokenStructs.sol

    Disclaimer