Introduction
We express our gratitude to the Venus team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
Venus is a decentralized finance (DeFi) algorithmic money market protocol on BNB Chain. Decentralized lending pools are very similar to traditional lending services offered by banks, except that they are offered by P2P decentralized platforms. Users can leverage assets by borrowing and lending assets listed in a pool. Lending pools help crypto holders earn a substantial income through interest paid on their supplied assets and access assets they don't currently own without selling any of their portfolio.
| title | content |
|---|---|
| Platform | BSC |
| Language | Solidity |
| Tags | Oracle |
| Timeline | 17/12/2022 - 26/04/2023 |
| Methodology | https://hackenio.cc/sc_methodology→ |
Review Scope | |
|---|---|
| Repository | https://github.com/VenusProtocol/oracle→ |
| Commit | 62ff8e2521ae7fa75431ec4ea71440a7694762ed |
Review Scope
- Repository
- https://github.com/VenusProtocol/oracle→
- Commit
- 62ff8e2521ae7fa75431ec4ea71440a7694762ed
Audit Summary
10/10
78.82%
10/10
10/10
The system users should acknowledge all the risks summed up in the risks section of the report
Document Information
This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.
The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for Venus |
| Audited By | Hacken |
| Website | https://venus.io/→ |
| Changelog | 23/12/2022 - Initial Review |
| 19/01/2023 - Second Review | |
| 10/04/2023 - Third Review | |
| 26/04/2023 - Fourth Review |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for Venus
- Audited By
- Hacken
- Website
- https://venus.io/→
- Changelog
- 23/12/2022 - Initial Review
- 19/01/2023 - Second Review
- 10/04/2023 - Third Review
- 26/04/2023 - Fourth Review
System Overview
Venus is an oracle system with following contracts:
ResilientOracle - oracle aggregator which includes functionality for setting, updating oracle configurations for various tokens, pausing and unpausing the contract, and retrieving prices from different sets of oracles for tokens.
BinanceOracle - the contract fetches prices of assets from Binance oracle.
BoundValidator - the contact is used to validate prices from two different sources, according to the upper and lower bound ratios config for each vToken in this contract.
ChainlinkOracle - contract which fetches prices of assets from Chain Link oracle.
PythOracle - contract which fetches prices of assets from Pyth oracle.
TwapOracle - contract which fetches prices of assets from PancakeSwap oracle.
Privileged roles
The owner of oracle may specify the contract which controls the list of access roles.
ResilientOracle - access to the functions is controlled by a set of custom roles. Functionality which is controlled by the roles:
Pausing/unpausing of the contract.
List of oracles for different tokens.
Enabling/disabling oracles.
BinanceOracle - no privileged roles.
BoundValidator - access to the functions is controlled by a set of custom roles. Functionality which is controlled by the roles:
Configuration of price boundaries.
ChainlinkOracle - access to the functions is controlled by a set of custom roles. Functionality which is controlled by the roles:
Setting tokens configurations.
Setting price feed addresses for different tokens.
PythOracle - access to the functions is controlled by a set of custom roles. Functionality which is controlled by the roles:
Setting tokens configurations.
Setting price feed addresses for different tokens.
TwapOracle - access to the functions is controlled by a set of custom roles:
Setting tokens configurations.
Setting price feed addresses for different tokens.
Executive Summary
Documentation quality
The total Documentation quality score is 10 out of 10.
Project description with technical details is provided.
Code is covered with the NatSpec comments.
Code quality
The total Code quality score is 10 out of 10.
Test coverage
Code coverage of the project is 78.82% (branch coverage).
Security score
Upon auditing, the code was found to contain 0 critical, 1 high, 5 medium, and 12 low severity issues. Out of these, 16 issues have been addressed and resolved, leading to a Security score of 10 out of 10.
All identified issues are detailed in the “Findings” section of this report.
Summary
The comprehensive audit of the customer's smart contract yields an overall score of 9.21. This score reflects the combined evaluation of documentation, code quality, test coverage, and security aspects of the project.
Risks
The oracle system highly relies on third party oracles; before using the system, it is necessary to make sure that all the oracle addresses are set up correctly.
The contracts in the system are upgradable, the logic may be updated by the owner.
The address of the contract, which controls the list of access roles, may be changed by the owner or set up incorrectly.
The Resilient Oracle aggregator contract may be paused.
The module responsible for the managing of access roles is out of the audit scope.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2023-0798 | Non-Finalized Code | fixed | High | |
| F-2023-0803 | Contradiction - Missing Validation | mitigated | Medium | |
| F-2023-0802 | Inefficient Gas Model - Redundant Library | fixed | Medium | |
| F-2023-0801 | Inefficient Gas Model - Redundant State Constant | fixed | Medium | |
| F-2023-0800 | Inefficient Gas Model | fixed | Medium | |
| F-2023-0799 | Missing Events Emitting | fixed | Medium | |
| F-2023-0815 | Inefficient Gas Model | unfixed | Low | |
| F-2023-0814 | Redundant Function | fixed | Low | |
| F-2023-0813 | Code Duplication | fixed | Low | |
| F-2023-0812 | Interface Marked As An Abstract Contract | fixed | Low |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/VenusProtocol/oracle→ |
| Commit | 62ff8e2521ae7fa75431ec4ea71440a7694762ed |
| Whitepaper | Provided |
| Requirements | Provided |
| Technical Requirements | Not provided |
Scope Details
- Repository
- https://github.com/VenusProtocol/oracle→
- Commit
- 62ff8e2521ae7fa75431ec4ea71440a7694762ed
- Whitepaper
- Provided
- Requirements
- Provided
- Technical Requirements
- Not provided