Introduction
We express our gratitude to the WhiteBIT team for the collaborative engagement that enabled the execution of this Smart Contract Security Assessment.
WhiteBIT is the largest European cryptocurrency exchange. WhiteBIT’s goal is to contribute to the mass adoption and popularization of blockchain technologies by implementing the most effective trading and staking tools on the most convenient terms.
| title | content |
|---|---|
| Platform | EVM |
| Language | Solidity |
| Timeline | 01/07/2023 - 08/09/2023 |
| Methodology | https://hackenio.cc/sc_methodology→ |
Review Scope | |
|---|---|
| Repository | https://github.com/whitebit-exchange/souls-ecosystem-contracts→ |
| Commit | f332570abecf5897e4ae9719577d78ab9f8ef0ab |
Review Scope
- Commit
- f332570abecf5897e4ae9719577d78ab9f8ef0ab
Audit Summary
10/10
100%
10/10
10/10
The system users should acknowledge all the risks summed up in the risks section of the report
Document Information
This report may contain confidential information about IT systems and the intellectual property of the Customer, as well as information about potential vulnerabilities and methods of their exploitation.
The report can be disclosed publicly after prior consent by another Party. Any subsequent publication of this report shall be without mandatory consent.
Document | |
|---|---|
| Name | Smart Contract Code Review and Security Analysis Report for WhiteBIT |
| Audited By | Hacken |
| Website | https://whitebit.com→ |
| Changelog | 04/07/2023 - Initial Review |
| 01/08/2023 - Second Review | |
| 08/09/2023 - Third Review |
Document
- Name
- Smart Contract Code Review and Security Analysis Report for WhiteBIT
- Audited By
- Hacken
- Website
- https://whitebit.com→
- Changelog
- 04/07/2023 - Initial Review
- 01/08/2023 - Second Review
- 08/09/2023 - Third Review
System Overview
WB Soul Ecosystem is a WB Network blockchain - based ecosystem designed to bring a comprehensive decentralized identity and attributes management system. Soulbound enables users to create unique identifiers called Souls, which are associated with their wallets, by supplying relevant information to the network. The network, in turn, associates Souls with two types of features - dynamic and immutable, through a system of smart contracts. Soulbound provides users with a decentralized platform for creating and managing digital identities with associated dynamic and permanent features on the blockchain.
The files in the scope:
EnumerableSet.sol - OpenZeppelin library for managing abstract data type of primitive types.
SoulRegistry.sol - Is a contract that enables the registration of Souls and the management of its addresses (associating/dissociating secondary addresses, changing the primary address). This contract is controlled by the owner (WhiteBIT), with the possibility of granting primary Soul addresses the ability to manage their list of secondary addresses.
SoulAttributeRegistry.sol - Is a contract that allows registering Soul Attributes and binding specific attributes to specific Souls. This contract facilitates the registration of Attribute and provides functionality to bind specific Attributes to specific Souls.
SoulBoundTokenRegistry.sol - The SoulBoundTokenRegistry contract is responsible for managing the binding of SoulBound tokens to Souls. The contract facilitates the association of a token from a specified collection to a particular Soul.
Ownable.sol - contract module from OpenZeppelin, which provides a basic access control. mechanism, where there is an account (an owner) that can be granted exclusive access to specific functions.
SoulRegistryConfig.sol - Simple registry configuration contract that provides addresses assignment rules.
Deployer.sol - Basic deployer contract for deploying all registries in a single place.
SoulLevel.sol - This contract implements the ISoulAttribute interface and represents the current Hold level of a user on WhiteBIT.
IsVerified.sol - This contract implements the ISoulAttribute interface and represents the current KYC verification status of a user on WhiteBIT.
ISoulAttributeRegistry.sol - The Interface of the SoulAttributeRegistry.sol.
ISoulBoundTokenRegistry.sol - The Interface of the SoulBoundTokenRegistry.sol.
Context.sol - Classic Context contract from OpenZeppelin.
SoulAttribute.sol - Contract with a predefined IERC165 methods.
ISoulBoundTokenCollection.sol - Interface of the SoulBoundTokenRegistry.sol.
ISoulRegistry.sol - The Interface of the SoulRegistry.sol.
ISoulFeature.sol - ISoulFeature is an interface for defining specific soul features.
ISoulFeatureRegistry.sol - Interface for SoulFeatureRegistry.sol.
IERC165.sol - The Interface of the ERC165 standard.
Privileged Roles
Owner privilege roles for Ownable.sol:
Transfers ownership of the contract to a new account.
Renounce ownership of the contract.
Owner privilege roles SoulFeatureRegistry.sol:
Ability to register new features.
Ability to pause registered features.
Ability to unpause paused features.
Owner privilege roles SoulRegistry.sol:
Register new soul using specified address as a primary address.
Change registered soul's primary address.
Assign new address to existing soul.
Owner privilege roles SoulRegistryConfig.sol:
Allow souls to manage addresses list.
Disallow souls to manage addresses list.
Update addresses per soul limit.
Executive Summary
Documentation quality
The total Documentation quality score is 10 out of 10.
Functional requirements are provided.
Technical description is provided.
NatSpecs are very good.
Code quality
The total Code quality score is 10 out of 10.
The development environment is configured.
Test coverage
Code coverage of the project is 100% (branch coverage).
Deployment and user interactions are covered with tests.
Security score
Upon auditing, the code was found to contain 0 critical, 0 high, 0 medium, and 2 low severity issues. Out of these, 2 issues have been addressed and resolved, leading to a Security score of 10 out of 10.
All identified issues are detailed in the “Findings” section of this report.
Summary
The comprehensive audit of the customer's smart contract yields an overall score of 10. This score reflects the combined evaluation of documentation, code quality, test coverage, and security aspects of the project.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2023-0924 | Copy Of Well Known Contract | fixed | Low | |
| F-2023-0923 | Missing Event Emitting | fixed | Low | |
| I-2023-0232 | Style Guide Violation | mitigated | Observation | |
| I-2023-0231 | Floating Pragma | fixed | Observation |
Appendix 1. Severity Definitions
When auditing smart contracts, Hacken is using a risk-based approach that considers Likelihood, Impact, Exploitability and Complexity metrics to evaluate findings and score severities.
Reference on how risk scoring is done is available through the repository in our Github organization:
Severity | Description |
|---|---|
Critical | Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation. |
High | High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation. |
Medium | Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category. |
Low | Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score. |
Severity
- Critical
Description
- Critical vulnerabilities are usually straightforward to exploit and can lead to the loss of user funds or contract state manipulation.
Severity
- High
Description
- High vulnerabilities are usually harder to exploit, requiring specific conditions, or have a more limited scope, but can still lead to the loss of user funds or contract state manipulation.
Severity
- Medium
Description
- Medium vulnerabilities are usually limited to state manipulations and, in most cases, cannot lead to asset loss. Contradictions and requirements violations. Major deviations from best practices are also in this category.
Severity
- Low
Description
- Major deviations from best practices or major Gas inefficiency. These issues will not have a significant impact on code execution, do not affect security score but can affect code quality score.
Appendix 2. Scope
The scope of the project includes the following smart contracts from the provided repository:
Scope Details | |
|---|---|
| Repository | https://github.com/whitebit-exchange/souls-ecosystem-contracts→ |
| Commit | f332570abecf5897e4ae9719577d78ab9f8ef0ab |
| Whitepaper | Not provided |
| Requirements | Provided |
| Technical Requirements | Provided |
Scope Details
- Commit
- f332570abecf5897e4ae9719577d78ab9f8ef0ab
- Whitepaper
- Not provided
- Requirements
- Provided
- Technical Requirements
- Provided