Closed Alexdefi closed 3 years ago
@Alexdefi The audit fee is 795 USDT. You may send USDT (ERC20 or BEP20) to: 0xb9662e592f2f0412be62f0833ca463a9b1aabebb or USDT (TRC20) to: TBzUKbek9AYVBwf91ykh3KY4Ushk95SCiB
The estimated auditing time - 7 days after payment.
Hi sir , we are ready to pay , last step , please discuss with me on twitter : https://twitter.com/DeFiFarmsNFTs thank you
Hi sir , we are ready to pay , last step , please discuss with me on twitter : https://twitter.com/DeFiFarmsNFTs thank you
I'm sorry, I don't use Twitter, you can contact with me in telegram https://t.me/yuriy77k
Or we may discuss it here
Have you received our payment? please start work
Yes, the payment was received and we started the audit
Great !
DeFiFarms protocol smart contract security audit report performed by Callisto Security Audit Department
DeFiFarms protocol is the first automatic liquidity acquisition yield farm and AMM decentralized exchange running on Binance Smart Chain with lots of unique and creative features that let you earn and win.
Upgradable proxy contract: https://bscscan.com/address/0x08d1Ed0e3816183e703a492dDD28d68fcc13bb61#code
Implementation contract: https://bscscan.com/address/0xd023618fa3d91f7862d277d59f2e8ad560df01fc#code
In total, 0 issues were reported, including:
0 high severity issues.
0 medium severity issues.
0 low severity issues.
In total, 11 notes were reported, including:
2 notes.
9 owner privileges.
No critical security issues were found.
require
In the function _transfer()
in the DefiFarmToken.sol
there are two requires conditions which couldn't be true
, because it already checks in the SafeMath
library:
Since the contract can accept BNB payment, somebody can transfer BNB to its address by mistake. A good security practice is to allow the owner to rescue BNB from the contract. It will not hurt the users because the contract should not hold BNB.
The contract owner can:
The contract's operator has the right to:
Swap And Liquify
function;Swap And Liquify
function.CREATE (0xf0)
opcode is assigned following this scheme keccak256(rlp([sender, nonce]))
. Therefore you need to use the same address that was originally used at the main chain to deploy the mock contract at a transaction with the nonce
that matches that on the original chain. Example: If you have deployed your main contract with address 0x010101 at your 2021th transaction then you need to increase your nonce of 0x010101 address to 2020 at the chain where your mock contract will be deployed. Then you can deploy your mock contract with your 2021th transaction, and it will receive the same address as your mainnet contract.The audited smart contract can be deployed. No security issues were found during the audit. Users have to pay attention to the owner's right to upgrade the contract on another which was not audited and may contain dangerous functionality.
It is recommended to adhere to the security practices described in pt. 4 of this report to ensure the contract's operability and prevent any issues that are not directly related to the code of this smart contract.
Thank you Sir @yuriy77k
Thank you verymuch
Please help me publish this result on Callisto and social platforms
Please find below the links of the blog post and our twitter publications:
Blog post: https://callisto.network/defifarms-protocol-security-audit/
Twitter: https://twitter.com/Callisto_Audits/status/1430597630464348168
Twitter FR: https://twitter.com/CallistoNetFr/status/1430597623317241856
Twitter RU: https://twitter.com/CallistoNetRu/status/1430597615171866632
...DeFiFarms protocol is the first automatic liquidity acquisition yield farm and AMM decentralized exchange running on Binance Smart Chain with lots of unique and creative features that let you earn and win.
https://bscscan.com/address/0x08d1Ed0e3816183e703a492dDD28d68fcc13bb61#code
Disclosure policy
Please reply to me privately via telegram : https://t.me/Alex_DeFiFarms We will record the positive ! Standard disclosure policy.
website : https://defifarms.org/
twitter : https://twitter.com/DeFiFarmsNFTs
https://t.me/Alex_DeFiFarms
Platform : : https://app.defifarms.org/
(** Important information, looking forward to hearing from you )