Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] SG Forge | ERC1155 | Aug2024

Date:

Sep 4, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Societe Generale Forge (SG Forge) team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

The SecurityToken is a custom, upgradeable ERC-1155 token.

Document

NameSmart Contract Code Review and Security Analysis Report for Societe Generale Forge (SG Forge)
Audited ByDavid Camps Novi
Approved ByPrzemyslaw Swiatowiec
Websitehttps://www.sgforge.com→
Changelog29/08/2024 - Preliminary Report; 04/09/2024 - Final Report
PlatformEthereum
LanguageSolidity
TagsUpgradeable; Proxy; ERC-1155
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for Societe Generale Forge (SG Forge)
    Audited By
    David Camps Novi
    Approved By
    Przemyslaw Swiatowiec
    Changelog
    29/08/2024 - Preliminary Report; 04/09/2024 - Final Report
    Platform
    Ethereum
    Language
    Solidity
    Tags
    Upgradeable; Proxy; ERC-1155

Review Scope

Repositoryprovided in zip file
CommitSHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d
  • Review Scope

    Repository
    provided in zip file
    Commit
    SHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d

Audit Summary

3Total Findings
2Resolved
1Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Functional requirements are present.

  • Technical description is provided.

Code quality

  • Best practices are not followed: F-2024-5607.

  • The development environment is configured.

Test coverage

Code coverage of the project is 100% (branch coverage).

  • Deployment and basic user interactions are covered with tests.

  • Negative cases coverage are provided missed.

System Overview

The SecurityToken is a custom, upgradeable ERC-1155 token with the following contracts:

SecurityTokenV1 - ERC1155 token with custom methods.

ERC1155AccessControlUpgradeableV1 - defines custom roles and access control mechanisms,

SatelliteV1 - implements ERC20 methods for tracking the tokens in block explorers.

Privileged roles

  • Registrar operator(for the whole contract) :

    • Mint tokens.

    • Burn tokens.

    • Force reviews(and either releases or cancels) transfers of tokens.

    • Name the operators for next implementation contract upgrade (ERC1155AccessControlUpgradeableV1.nameNewOperators).

    • Authorise upgrade to next implementation contract (ERC1155AccessControlUpgradeableV1.authorizeImplementation).

    • Pause/Unpause the contract.

    • Set URI parameters.

    • Define the settlement and registrar agents.

  • Technical operator(for the whole contract):

    • Only the technical operator can launch a (previously authorised) upgrade of the implementation contract (upgradeTo/upgradeToAndCall).

  • Registrar agent operator(by tokenId):

    • Initiate a safeTransferFrom

    • Cancel a locked safeTransferFrom using the cancelTransaction method.

  • Settlement agent operator(by tokenId):

    • Release a locked safeTransferFrom using the releaseTransaction method.

Risks

The project utilizes Solidity version 0.8.26, which includes the introduction of the PUSHO (0x5f) opcode. This opcode is currently supported on the Ethereum mainnet but may not be universally supported across other blockchain networks. Consequently, deploying the contract on chains other than the Ethereum mainnet, such as certain Layer 2 (L2) chains or alternative networks, might lead to compatibility issues or execution errors due to the lack of support for the PUSHO opcode. In scenarios where deployment on various chains is anticipated, selecting an appropriate Ethereum Virtual Machine (EVM) version that is widely supported across these networks is crucial to avoid potential operational disruptions or deployment failures.

The project's contracts are upgradable, allowing the administrator to update the contract logic at any time. While this provides flexibility in addressing issues and evolving the project, it also introduces risks if upgrade processes are not properly managed or secured, potentially allowing for unauthorized changes that could compromise the project's integrity and security.

The protocol is fully centralized, and all operations for minting and managing transactions are supervised by the system roles.

Findings

F-2024-5608The Project Includes an Incorrect README
Status
fixed
Severity

Observation
F-2024-5607Use of Immutable Variables for Implementation
Status
accepted
Severity

Observation
F-2024-5606Missing Event for Key Value Update
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-5608The Project Includes an Incorrect README
fixed

Observation
F-2024-5607Use of Immutable Variables for Implementation
accepted

Observation
F-2024-5606Missing Event for Key Value Update
fixed

Observation
1-3 of 3 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Severity Definitions

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Scope Details

Repositoryprovided in zip file
CommitSHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d
Whitepaper-
Requirements./README.md
Technical Requirements./README.md
  • Scope Details

    Repository
    provided in zip file
    Commit
    SHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d
    Whitepaper
    -
    Requirements
    ./README.md
    Technical Requirements
    ./README.md

Contracts in Scope

contracts
v1
satellite
ISatelliteV1.sol (SHA3: d7f68ee284d47d601d0df4f949683f5722346f9508947bde0b92890a3efe1cee) - contracts › v1 › satellite › ISatelliteV1.sol (SHA3: d7f68ee284d47d601d0df4f949683f5722346f9508947bde0b92890a3efe1cee)
SatelliteV1.sol (SHA3: b079f9a3e8724f5d848767c6ac82c8e281e380f08e7b440c1583795dc8449bb0 - contracts › v1 › satellite › SatelliteV1.sol (SHA3: b079f9a3e8724f5d848767c6ac82c8e281e380f08e7b440c1583795dc8449bb0
securityToken
IERC1155AccessControlUpgradeableV1.sol (SHA3: a58a54dd24a61801d159778df0fcc5d861d67da4aebd457a1ec8ce57a2e68540) - contracts › v1 › securityToken › IERC1155AccessControlUpgradeableV1.sol (SHA3: a58a54dd24a61801d159778df0fcc5d861d67da4aebd457a1ec8ce57a2e68540)
ERC1155AccessControlUpgradeableV1.sol (SHA3: 782031e16200da27493de0bf4c5fb2b81cb645fefd40e8929c2a81d1dc203716) - contracts › v1 › securityToken › ERC1155AccessControlUpgradeableV1.sol (SHA3: 782031e16200da27493de0bf4c5fb2b81cb645fefd40e8929c2a81d1dc203716)
ISecurityTokenV1.sol (SHA3: fb5d8848347221ba8c145147d3a061319f7259b0d3f407267114318d7a4cdae0) - contracts › v1 › securityToken › ISecurityTokenV1.sol (SHA3: fb5d8848347221ba8c145147d3a061319f7259b0d3f407267114318d7a4cdae0)
SecurityTokenV1.sol (SHA3: d6ac67258e060e1bdce3cbb5ddc2e9aa1f9714a33a99e13ba96cde2377eb6bac) - contracts › v1 › securityToken › SecurityTokenV1.sol (SHA3: d6ac67258e060e1bdce3cbb5ddc2e9aa1f9714a33a99e13ba96cde2377eb6bac)

Disclaimer