Introduction
We express our gratitude to the Summoners Arena Ltd team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
Summoners Arena is a scalable and interoperable blockchain gaming infrastructure provider.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for Summoners Arena Ltd |
| Audited By | Philipp Eder |
| Approved By | Turgay Arda Usman |
| Website | https://saworld.io/→ |
| Changelog | 21/08/2024 - Preliminary Report & 22/08/2024 - Final Report |
| Platform | EVM |
| Language | Solidity |
| Tags | ERC-20, GameFi |
| Methodology | https://hackenio.cc/sc_methodology→ |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for Summoners Arena Ltd
- Audited By
- Philipp Eder
- Approved By
- Turgay Arda Usman
- Website
- https://saworld.io/→
- Changelog
- 21/08/2024 - Preliminary Report & 22/08/2024 - Final Report
- Platform
- EVM
- Language
- Solidity
- Tags
- ERC-20, GameFi
- Methodology
- https://hackenio.cc/sc_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/onechain-game/SummonersArenaContracts→ |
| Commit | 239ae79 |
Review Scope
- Commit
- 239ae79
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
Functional requirements are provided.
Technical description is sufficient.
Code quality
The code does not follow best practices in terms of gas efficiency.
The NatSpecs are missing.
The development environment is configured.
Test coverage
Code coverage of the project is 0% (branch coverage).
Tests are not mandatory for projects with less than 250 LoC.
System Overview
Summoners Arena is a blockchain gaming protocol with the following contracts submitted for audit:
SAE — simple ERC-20 token that mints all initial supply to a deployer. Additional minting is not allowed. The owner has the ability to pause and unpause the contract as well as blacklisting user's addresses and removing user's addresses from the blacklist.
It has the following attributes:
Name: SA World Energy
Symbol: SAE
Decimals: 18
Total supply: 500 Million Tokens.
Privileged roles
The owner has the ability to pause and unpause the contract.
The owner has the ability to blacklist user's addresses and remove user's addresses from the blacklist.
Risks
The owner of the contract has the privilege to add any user's address to the blacklist resulting in their funds being frozen.
The owner of the contract has the privilege to pause the contract at any time rendering the contract unusable.
Fixed Total Supply Post-Deployment: The token’s total supply is determined at deployment and cannot be verified beforehand, potentially limiting the project’s adaptability and economic model flexibility.
Centralized Minting to a Single Address: The project concentrates minting tokens in a single address, raising the risk of fund mismanagement or theft, especially if key storage security is compromised.
Absence of a Token Burn Mechanism: The project lacks a mechanism to burn tokens, facing challenges in managing supply dynamically, affecting the token's value stability and inflation control.
Single Points of Failure and Control: The project is fully or partially centralized, introducing single points of failure and control. This centralization can lead to vulnerabilities in decision-making and operational processes, making the system more susceptible to targeted attacks or manipulation.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-5458 | Poor readability of large numerals | fixed | Observation | |
| F-2024-5457 | Constants should be defined rather than using magic numbers | fixed | Observation | |
| F-2024-5433 | Gas inefficiency in blacklist update | fixed | Observation | |
| F-2024-5424 | Functions not used internally can be marked as external | fixed | Observation | |
| F-2024-5422 | Floating Pragma | fixed | Observation |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/onechain-game/SummonersArenaContracts→ |
| Commit | 239ae79d9edd076c660a3100d6c286248294f2b1 |
| Deployed Address | 0x1f310af15E1c5E224f998660A6011F34117c5408 (Ethereum Mainnet) |
| Whitepaper | https://docs.saworld.io/→ |
| Requirements | https://docs.saworld.io/token/overview→ |
| Technical Requirements | https://docs.saworld.io/token/overview→ |
Scope Details
- Commit
- 239ae79d9edd076c660a3100d6c286248294f2b1
- Deployed Address
- 0x1f310af15E1c5E224f998660A6011F34117c5408 (Ethereum Mainnet)
- Whitepaper
- https://docs.saworld.io/→
- Requirements
- https://docs.saworld.io/token/overview→
- Technical Requirements
- https://docs.saworld.io/token/overview→