Introduction
We express our gratitude to the Venator Universe team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
The VNT token is utilized both in the in-game market and on external exchanges. It is a token with a limited total supply, ensuring its scarcity and value. Players can find VNT tokens inside Dungeon Chests within the game, making it a valuable in-game currency. These tokens facilitate the buying and selling of items between players.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for Venator Universe |
| Audited By | Przemyslaw Swiatowiec |
| Approved By | Ataberk Yavuzer |
| Website | https://www.venatoruniverse.com/→ |
| Changelog | 26/07/2024 - Preliminary Report |
| 12/08/2024 - Final Report | |
| Platform | Whitechain |
| Language | Solidity |
| Tags | ERC20, Vesting, Pre-Sale |
| Methodology | https://hackenio.cc/sc_methodology→ |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for Venator Universe
- Audited By
- Przemyslaw Swiatowiec
- Approved By
- Ataberk Yavuzer
- Changelog
- 26/07/2024 - Preliminary Report
- 12/08/2024 - Final Report
- Platform
- Whitechain
- Language
- Solidity
- Tags
- ERC20, Vesting, Pre-Sale
- Methodology
- https://hackenio.cc/sc_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/VenatorGames/live-contracts-hardhat→ |
| Commit | 69069b599152a5889ecf0d4c1e73ad132a66efd5 |
Review Scope
- Commit
- 69069b599152a5889ecf0d4c1e73ad132a66efd5
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
Functional requirements are provided.
Technical description is provided.
Code quality
No code quality issues were identified.
Test coverage
The test coverage of the project is 56.73%.
System Overview
The VNT ecosystem consists of two primary smart contracts: VNTPreSale and VenatorToken. These contracts work together to manage the pre-sale, distribution, and utility of VNT tokens within the game and external markets.
VNTPreSale Contract
The VNTPreSale contract is responsible for managing the pre-sale event where users can purchase VNT tokens using USDC. The key features of this contract include:
Token Purchase: Users can buy VNT tokens during the sale period by paying in USDC. The price is set at 0.22 USDC per VNT.
Sale Period Management: The contract enforces the sale start and end times, ensuring that token purchases can only occur within the specified period.
Lock and Release Mechanism: Tokens purchased during the pre-sale are locked for an initial period of 4 months. After the lock period, 10% of the tokens are released each month over the next 10 months.
Event Emissions: The contract emits events for significant actions such as token purchases, token releases, and updates to critical contract parameters.
VenatorToken Contract
The VenatorToken contract implements the ERC20 standard and includes additional functionalities such as pausing transfers, burning tokens, and banning addresses. Key features of this contract include:
Total Supply Management: The contract ensures a maximum supply of 100,000,000 VNT tokens.
Minting: The contract allows the owner to mint new tokens, up to the maximum supply.
Burning: Users can burn their tokens, reducing the total supply.
Pausing: The contract owner can pause and unpause all token transfers, useful for emergency situations.
Address Ban/Unban: The contract owner can ban and unban addresses, preventing them from transferring or receiving tokens.
Privileged roles
The system has the owner role that has the authority to perform administrative and sensitive operations within the contracts.
VNTPreSale Contract:
Set Sale Parameters: The owner can set or update the start and end timestamps of the sale, token price, lock period, and other critical parameters.
Update Token Addresses: The owner can update the addresses of the VNT and USDC tokens.
Update Bank Address: The owner can change the VNT bank address where tokens are held for the pre-sale and release.
Emergency Functions: The owner can pause or unpause the sale if required.
VenatorToken Contract:
Minting: The owner can mint new VNT tokens up to the maximum supply.
Pausing: The owner can pause and unpause all token transfers.
Banning/Unbanning Addresses: The owner can ban addresses from transferring or receiving tokens and later unban them.
Emergency Functions: The owner can implement measures such as pausing all contract functions if a critical issue arises.
Risks
The contract owner's ability to ban and unban users is intended as a safeguard against hackers, locking stolen tokens to protect legitimate users. However, this functionality also introduces the risk of increased centralization and potential misuse, as it could arbitrarily prevent token transfers and restrict user activities.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2024-4423 | Lack of Slippage Control for Token Purchases | fixed | Medium | |
| F-2024-4443 | Permit Function Bypasses Banned Address Restriction | fixed | Low | |
| F-2024-4426 | VNT Bank Allowance and Address Modification Risks Impact Token Claims | fixed | Low | |
| F-2024-4424 | Modifiable Vesting Terms and Critical Addresses Impact User Transactions | fixed | Low | |
| F-2024-4453 | Redundant Allowance Check in Token Purchase Function | fixed | Observation | |
| F-2024-4452 | Gas Inefficiency Due to Missing Usage of Solidity Custom Errors | fixed | Observation | |
| F-2024-4454 | Floating Pragma and Unsupported Solidity Version on Whitechain | fixed | Observation | |
| F-2024-4430 | Incomplete Documentation of Token Lock and Vesting Periods | fixed | Observation | |
| F-2024-4429 | Minting Mechanism Allows Circumvention of Burned Tokens | fixed | Observation | |
| F-2024-4428 | Rounding Issue Allows Purchase of Tokens for Zero USDC | fixed | Observation |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/VenatorGames/live-contracts→ |
| Commit | 69069b599152a5889ecf0d4c1e73ad132a66efd5 |
| Whitepaper | https://whitepaper.venatoruniverse.com/→ |
| Requirements | https://whitepaper.venatoruniverse.com/→ |
| Technical Requirements | https://whitepaper.venatoruniverse.com/→ |
Scope Details
- Commit
- 69069b599152a5889ecf0d4c1e73ad132a66efd5
- Whitepaper
- https://whitepaper.venatoruniverse.com/→
- Requirements
- https://whitepaper.venatoruniverse.com/→
- Technical Requirements
- https://whitepaper.venatoruniverse.com/→