Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[SCA] Venator Universe | Live-Contracts | Jul2024

Date:

Aug 13, 2024

Table of Content

→Introduction
→Audit Summary
→System Overview
→Risks
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the Venator Universe team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.

The VNT token is utilized both in the in-game market and on external exchanges. It is a token with a limited total supply, ensuring its scarcity and value. Players can find VNT tokens inside Dungeon Chests within the game, making it a valuable in-game currency. These tokens facilitate the buying and selling of items between players.

Document

NameSmart Contract Code Review and Security Analysis Report for Venator Universe
Audited ByPrzemyslaw Swiatowiec
Approved ByAtaberk Yavuzer
Websitehttps://www.venatoruniverse.com/→
Changelog26/07/2024 - Preliminary Report
12/08/2024 - Final Report
PlatformWhitechain
LanguageSolidity
TagsERC20, Vesting, Pre-Sale
Methodologyhttps://hackenio.cc/sc_methodology→
  • Document

    Name
    Smart Contract Code Review and Security Analysis Report for Venator Universe
    Audited By
    Przemyslaw Swiatowiec
    Approved By
    Ataberk Yavuzer
    Changelog
    26/07/2024 - Preliminary Report
    12/08/2024 - Final Report
    Platform
    Whitechain
    Language
    Solidity
    Tags
    ERC20, Vesting, Pre-Sale

Review Scope

Repositoryhttps://github.com/VenatorGames/live-contracts-hardhat→
Commit69069b599152a5889ecf0d4c1e73ad132a66efd5

Audit Summary

12Total Findings
12Resolved
0Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • Functional requirements are provided.

  • Technical description is provided.

Code quality

  • No code quality issues were identified.

Test coverage

The test coverage of the project is 56.73%.

System Overview

The VNT ecosystem consists of two primary smart contracts: VNTPreSale and VenatorToken. These contracts work together to manage the pre-sale, distribution, and utility of VNT tokens within the game and external markets.

VNTPreSale Contract

The VNTPreSale contract is responsible for managing the pre-sale event where users can purchase VNT tokens using USDC. The key features of this contract include:

  • Token Purchase: Users can buy VNT tokens during the sale period by paying in USDC. The price is set at 0.22 USDC per VNT.

  • Sale Period Management: The contract enforces the sale start and end times, ensuring that token purchases can only occur within the specified period.

  • Lock and Release Mechanism: Tokens purchased during the pre-sale are locked for an initial period of 4 months. After the lock period, 10% of the tokens are released each month over the next 10 months.

  • Event Emissions: The contract emits events for significant actions such as token purchases, token releases, and updates to critical contract parameters.

VenatorToken Contract

The VenatorToken contract implements the ERC20 standard and includes additional functionalities such as pausing transfers, burning tokens, and banning addresses. Key features of this contract include:

  • Total Supply Management: The contract ensures a maximum supply of 100,000,000 VNT tokens.

  • Minting: The contract allows the owner to mint new tokens, up to the maximum supply.

  • Burning: Users can burn their tokens, reducing the total supply.

  • Pausing: The contract owner can pause and unpause all token transfers, useful for emergency situations.

  • Address Ban/Unban: The contract owner can ban and unban addresses, preventing them from transferring or receiving tokens.

Privileged roles

The system has the owner role that has the authority to perform administrative and sensitive operations within the contracts.

VNTPreSale Contract:

  • Set Sale Parameters: The owner can set or update the start and end timestamps of the sale, token price, lock period, and other critical parameters.

  • Update Token Addresses: The owner can update the addresses of the VNT and USDC tokens.

  • Update Bank Address: The owner can change the VNT bank address where tokens are held for the pre-sale and release.

  • Emergency Functions: The owner can pause or unpause the sale if required.

VenatorToken Contract:

  • Minting: The owner can mint new VNT tokens up to the maximum supply.

  • Pausing: The owner can pause and unpause all token transfers.

  • Banning/Unbanning Addresses: The owner can ban addresses from transferring or receiving tokens and later unban them.

  • Emergency Functions: The owner can implement measures such as pausing all contract functions if a critical issue arises.

Risks

The contract owner's ability to ban and unban users is intended as a safeguard against hackers, locking stolen tokens to protect legitimate users. However, this functionality also introduces the risk of increased centralization and potential misuse, as it could arbitrarily prevent token transfers and restrict user activities.

Findings

F-2024-4423Lack of Slippage Control for Token Purchases
Status
fixed
Severity

Medium
F-2024-4443Permit Function Bypasses Banned Address Restriction
Status
fixed
Severity

Low
F-2024-4426VNT Bank Allowance and Address Modification Risks Impact Token Claims
Status
fixed
Severity

Low
F-2024-4424Modifiable Vesting Terms and Critical Addresses Impact User Transactions
Status
fixed
Severity

Low
F-2024-4453Redundant Allowance Check in Token Purchase Function
Status
fixed
Severity

Observation
F-2024-4452Gas Inefficiency Due to Missing Usage of Solidity Custom Errors
Status
fixed
Severity

Observation
F-2024-4454Floating Pragma and Unsupported Solidity Version on Whitechain
Status
fixed
Severity

Observation
F-2024-4430Incomplete Documentation of Token Lock and Vesting Periods
Status
fixed
Severity

Observation
F-2024-4429Minting Mechanism Allows Circumvention of Burned Tokens
Status
fixed
Severity

Observation
F-2024-4428Rounding Issue Allows Purchase of Tokens for Zero USDC
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2024-4423Lack of Slippage Control for Token Purchases
fixed

Medium
F-2024-4443Permit Function Bypasses Banned Address Restriction
fixed

Low
F-2024-4426VNT Bank Allowance and Address Modification Risks Impact Token Claims
fixed

Low
F-2024-4424Modifiable Vesting Terms and Critical Addresses Impact User Transactions
fixed

Low
F-2024-4453Redundant Allowance Check in Token Purchase Function
fixed

Observation
F-2024-4452Gas Inefficiency Due to Missing Usage of Solidity Custom Errors
fixed

Observation
F-2024-4454Floating Pragma and Unsupported Solidity Version on Whitechain
fixed

Observation
F-2024-4430Incomplete Documentation of Token Lock and Vesting Periods
fixed

Observation
F-2024-4429Minting Mechanism Allows Circumvention of Burned Tokens
fixed

Observation
F-2024-4428Rounding Issue Allows Purchase of Tokens for Zero USDC
fixed

Observation
1-10 of 12 findings

Identify vulnerabilities in your smart contracts.

Appendix 1. Severity Definitions

When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.

Reference on how risk scoring is done is available through the repository in our Github organization:

Severity

Description

Critical
Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

High
High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

Medium
Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

Low
Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
  • Severity

    Critical

    Description

    Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.

    Severity

    High

    Description

    High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.

    Severity

    Medium

    Description

    Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.

    Severity

    Low

    Description

    Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.

Appendix 2. Scope

The scope of the project includes the following smart contracts from the provided repository:

Contracts in Scope

contracts
VenatorToken.sol - contracts › VenatorToken.sol
VNTPreSale.sol - contracts › VNTPreSale.sol

Disclaimer