Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[L1] Sunrise | SunriseLayer | Aug2024

Date:

Oct 15, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Sunrise team for the collaborative engagement that enabled the execution of this Blockchain Protocol Security Assessment.

Sunrise is a specialized Data Availability (DA) Layer for Proof of Liquidity and Fee Abstraction, supporting the modular paradigm by allowing developers to build rollups/apps with enhanced security and liquidity. Sunrise extends Berachain's Proof of Liquidity (PoL) model to L2s, while retaining compatibility with Celestia architecture. A modular cross-chain yield hub (Gluon) is deployed as a Sovereign Rollup (L2) onto the Sunrise L1 blockchain.

Document

NameBlockchain Protocol Review and Security Analysis Report for Sunrise
Audited ByReza Mirjahanian
Approved ByNino Lipartiia
Websitehttps://sunriselayer.io→
Changelog13/09/2024 - Preliminary Report
Changelog15/10/2024 - Final Report
PlatformSunrise
LanguageGolang
TagsCosmos, Proof of Liquidity
Methodologyhttps://hackenio.cc/blockchain_methodology→

Review Scope

Repositoryhttps://github.com/sunriselayer/sunrise→
Commitf0cf6a9e1adaec7f2e594a6fe9af26b8c80c64a7

Audit Summary

5Total Findings
2Resolved
2Accepted
1Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • The documentation for the installation and build process is well-structured and accessible.

  • Additional detailed documentation for each module would enhance clarity and understanding.

  • Code comments are present but could benefit from greater detail in certain areas.

Code quality

  • High code quality is consistently maintained across the project.

  • Robust error handling mechanisms contribute to system stability and make debugging more efficient.

  • Increasing unit and end-to-end (e2e) test coverage is recommended to further improve reliability and maintainability.

Architecture quality

  • The project is built on the robust foundation of the Cosmos SDK.

  • All necessary modifications have been carefully implemented to align with Sunrise's specific requirements.

  • The modular design supports ease of maintenance and facilitates future scalability.

System Overview

Sunrise is a specialized Data Availability (DA) Layer designed for Proof of Liquidity and Fee Abstraction, enabling developers to build rollups and applications with enhanced security and liquidity within a modular framework.

This audit report provides a comprehensive analysis of the custom modules within the Sunrise Data Availability Layer, specifically:

  • x/swap: Facilitates token swaps using liquidity from the x/liquiditypool module.

  • x/liquiditypool: Manages liquidity pools utilizing a concentrated liquidity Automated Market Maker (AMM) mechanism.

  • x/liquidityincentive: Oversees the distribution of incentive rewards to liquidity providers within the liquidity pools.

Findings

F-2024-5459Critical Vulnerabilities in External Go Dependencies
Status
fixed
Severity

Critical
F-2024-6059Potential Division by Zero in Liquidity Pool Calculations
Status
fixed
Severity

Observation
F-2024-5838Telemetry Configs
Status
accepted
Severity

Observation
F-2024-5757Enhancements for Code Consistency and Efficiency
Status
mitigated
Severity

Observation
F-2024-5499Code Quality Deficiencies Highlighted by Static Analysis
Status
accepted
Severity

Observation
Code
―
Title
Status
Severity
F-2024-5459Critical Vulnerabilities in External Go Dependencies
fixed

Critical
F-2024-6059Potential Division by Zero in Liquidity Pool Calculations
fixed

Observation
F-2024-5838Telemetry Configs
accepted

Observation
F-2024-5757Enhancements for Code Consistency and Efficiency
mitigated

Observation
F-2024-5499Code Quality Deficiencies Highlighted by Static Analysis
accepted

Observation
1-5 of 5 findings

Findings like these can secure your blockchain.

Appendix 1. Severity Definitions

Severity

Description

Critical
Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

High
High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

Medium
Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

Low
Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.
  • Severity

    Critical

    Description

    Vulnerabilities that can lead to a complete breakdown of the blockchain network's security, privacy, integrity, or availability fall under this category. They can disrupt the consensus mechanism, enabling a malicious entity to take control of the majority of nodes or facilitate 51% attacks. In addition, issues that could lead to widespread crashing of nodes, leading to a complete breakdown or significant halt of the network, are also considered critical along with issues that can lead to a massive theft of assets. Immediate attention and mitigation are required.

    Severity

    High

    Description

    High severity vulnerabilities are those that do not immediately risk the complete security or integrity of the network but can cause substantial harm. These are issues that could cause the crashing of several nodes, leading to temporary disruption of the network, or could manipulate the consensus mechanism to a certain extent, but not enough to execute a 51% attack. Partial breaches of privacy, unauthorized but limited access to sensitive information, and affecting the reliable execution of smart contracts also fall under this category.

    Severity

    Medium

    Description

    Medium severity vulnerabilities could negatively affect the blockchain protocol but are usually not capable of causing catastrophic damage. These could include vulnerabilities that allow minor breaches of user privacy, can slow down transaction processing, or can lead to relatively small financial losses. It may be possible to exploit these vulnerabilities under specific circumstances, or they may require a high level of access to exploit effectively.

    Severity

    Low

    Description

    Low severity vulnerabilities are minor flaws in the blockchain protocol that might not have a direct impact on security but could cause minor inefficiencies in transaction processing or slight delays in block propagation. They might include vulnerabilities that allow attackers to cause nuisance-level disruptions or are only exploitable under extremely rare and specific conditions. These vulnerabilities should be corrected but do not represent an immediate threat to the system.

Appendix 2. Scope

The scope of the project includes the following components from the provided repository:

Scope Details

Repositoryhttps://github.com/sunriselayer/sunrise→
Commitf0cf6a9e1adaec7f2e594a6fe9af26b8c80c64a7

Components in Scope

Custom Modules:

  • Review of custom module liquiditypool

  • Review of custom module swap

  • Review of custom module liquidityincentive

Assets in Scope

Custom Modules - Custom Modules
Custom Module LP - Custom Module LP
Custom Module Swap - Custom Module Swap
Dependencies - Dependencies
Code quality - Code quality

Disclaimer