Introduction
We express our gratitude to the Societe Generale Forge (SG Forge) team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
The SecurityToken is a custom, upgradeable ERC-1155 token.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for Societe Generale Forge (SG Forge) |
| Audited By | David Camps Novi |
| Approved By | Przemyslaw Swiatowiec |
| Website | https://www.sgforge.com→ |
| Changelog | 29/08/2024 - Preliminary Report; 04/09/2024 - Final Report |
| Platform | Ethereum |
| Language | Solidity |
| Tags | Upgradeable; Proxy; ERC-1155 |
| Methodology | https://hackenio.cc/sc_methodology→ |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for Societe Generale Forge (SG Forge)
- Audited By
- David Camps Novi
- Approved By
- Przemyslaw Swiatowiec
- Website
- https://www.sgforge.com→
- Changelog
- 29/08/2024 - Preliminary Report; 04/09/2024 - Final Report
- Platform
- Ethereum
- Language
- Solidity
- Tags
- Upgradeable; Proxy; ERC-1155
- Methodology
- https://hackenio.cc/sc_methodology→
Review Scope | |
|---|---|
| Repository | provided in zip file |
| Commit | SHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d |
Review Scope
- Repository
- provided in zip file
- Commit
- SHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
Functional requirements are present.
Technical description is provided.
Code quality
Best practices are not followed: F-2024-5607.
The development environment is configured.
Test coverage
Code coverage of the project is 100% (branch coverage).
Deployment and basic user interactions are covered with tests.
Negative cases coverage are provided missed.
System Overview
The SecurityToken is a custom, upgradeable ERC-1155 token with the following contracts:
SecurityTokenV1 - ERC1155 token with custom methods.
ERC1155AccessControlUpgradeableV1 - defines custom roles and access control mechanisms,
SatelliteV1 - implements ERC20 methods for tracking the tokens in block explorers.
Privileged roles
Registrar operator(for the whole contract) :
Mint tokens.
Burn tokens.
Force reviews(and either releases or cancels) transfers of tokens.
Name the operators for next implementation contract upgrade (ERC1155AccessControlUpgradeableV1.nameNewOperators).
Authorise upgrade to next implementation contract (ERC1155AccessControlUpgradeableV1.authorizeImplementation).
Pause/Unpause the contract.
Set URI parameters.
Define the settlement and registrar agents.
Technical operator(for the whole contract):
Only the technical operator can launch a (previously authorised) upgrade of the implementation contract (upgradeTo/upgradeToAndCall).
Registrar agent operator(by tokenId):
Initiate a safeTransferFrom
Cancel a locked safeTransferFrom using the cancelTransaction method.
Settlement agent operator(by tokenId):
Release a locked safeTransferFrom using the releaseTransaction method.
Risks
The project utilizes Solidity version 0.8.26, which includes the introduction of the PUSHO (0x5f) opcode. This opcode is currently supported on the Ethereum mainnet but may not be universally supported across other blockchain networks. Consequently, deploying the contract on chains other than the Ethereum mainnet, such as certain Layer 2 (L2) chains or alternative networks, might lead to compatibility issues or execution errors due to the lack of support for the PUSHO opcode. In scenarios where deployment on various chains is anticipated, selecting an appropriate Ethereum Virtual Machine (EVM) version that is widely supported across these networks is crucial to avoid potential operational disruptions or deployment failures.
The project's contracts are upgradable, allowing the administrator to update the contract logic at any time. While this provides flexibility in addressing issues and evolving the project, it also introduces risks if upgrade processes are not properly managed or secured, potentially allowing for unauthorized changes that could compromise the project's integrity and security.
The protocol is fully centralized, and all operations for minting and managing transactions are supervised by the system roles.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-5608 | The Project Includes an Incorrect README | fixed | Observation | |
| F-2024-5607 | Use of Immutable Variables for Implementation | accepted | Observation | |
| F-2024-5606 | Missing Event for Key Value Update | fixed | Observation |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | provided in zip file |
| Commit | SHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d |
| Whitepaper | - |
| Requirements | ./README.md |
| Technical Requirements | ./README.md |
Scope Details
- Repository
- provided in zip file
- Commit
- SHA256: 7d0c879aef564560ca2c8ac93710d1c100fb999472e2b695acb5b4c6f5a20f8d
- Whitepaper
- -
- Requirements
- ./README.md
- Technical Requirements
- ./README.md