- $33,250 USDC main award pot
- $1,750 USDC gas optimization award pot
- Join C4 Discord to register
- Submit findings using the C4 form
- Read our guidelines for more details
- Starts August 12, 2022 20:00 UTC
- Ends August 15, 2022 20:00 UTC
| File | SLOC | Coverage |
|---|---|---|
| Contracts (2) | ||
| contracts/features/Blocklist.sol ๐ฅ | 27 | 100.00% |
| contracts/VotingEscrow.sol ๐ค | 670 | 97.52% |
| Interfaces (3) | ||
| contracts/interfaces/IBlocklist.sol | 4 | 100.00% |
| contracts/interfaces/IVotingEscrow.sol | 20 | 100.00% |
| contracts/interfaces/IERC20.sol | 25 | 100.00% |
| Total (over 5 files): | 746 | 97.59% |
| File | SLOC | Coverage |
|---|---|---|
| Contracts (2) | ||
| contracts/libraries/ReentrancyBlock.sol | 10 | 0.00% |
| contracts/libraries/Authorizable.sol | 31 | 40.00% |
| Abstracts (2) | ||
| contracts/libraries/ERC20PermitWithMint.sol | 34 | 41.67% |
| contracts/libraries/ERC20Permit.sol ๐งฎ ๐ | 122 | 62.86% |
| Interfaces (1) | ||
| contracts/interfaces/IERC20Permit.sol | 15 | 100.00% |
| Total (over 5 files): | 212 | 50.82% |
- @openzeppelin/contracts/security/ReentrancyGuard.sol
export ALCHEMY_MAINNET_API_KEY=<your-api-key-goes-here> && rm -Rf 2022-08-fiatdao || true && git clone https://github.com/code-423n4/2022-08-fiatdao && cd 2022-08-fiatdao && npm install && npm run build && npm run test
A solidity implementation of Curve's voting-escrow with additional features outlined below.
Lock delegation Users may delegate ther lock to another user whereby they give the delegatee control over their lock expiration and balance (i.e. voting power). Both users, the delegator and the delegatee, need to have an active lock in place at the time of delegation. Moreover, the delegatee's lock expiration needs to be longer than the delegator's.
Lock quitting A non-expired lock may be quitted by the lock owner anytime. The lock cannot be delegated at the time of quitting and the quitter pays a penalty proportional to the remaining lock duration.
Optimistic SmartWallet approval SmartWallets (i.e. contracts) can create a lock without being approved first. However, the veFDT owner maintains a Blocklist where SmartWallets may be blocked from further interacting with the system. The Blocklist only allows the owner to block contracts but not EOAs. Blocked SmartWallets may still undelegate (if delegated prior to the blocking) and quit their lock (by paying the penalty) or withdraw once the lock expired.
npm installnpm run buildnpm run testNote: We use hardhat and Alchemy web3 provider in order to test against Ethereum mainnet state. Make sure to configure an Alchemy API endpoint with a valid key before running the test script:
export ALCHEMY_MAINNET_API_KEY=[ALCHEMY_KEY]The veFDT contract implements the same checkpoint mathematics than the original Curve VotingEscrow.vy contract. The new features leverage this math in order to void or redirect (i.e. delegate) a lock's virtual balance. More details about how the various lock operations interact with Curve's checkpoint math can be found here.
- Curve Finance: Original concept and implementation in Vyper (Source)
- mStable: Forking Curve's Vyper contract and porting to Solidity including math tests (Source)
- Do you have a link to the repo that the contest will cover? https://github.com/fiatdao/veFDT (private repo)
- How many (non-library) contracts are in the scope? 5
- Total sLoC in these contracts? 746
- How many library dependencies? 1
- How many separate interfaces and struct definitions are there for the contracts within scope? 3
- Does most of your code generally use composition or inheritance? no
- How many external calls? 1
- Is there a need to understand a separate part of the codebase / get context in order to audit this part of the protocol? false
- Does it use an oracle? false
- Does the token conform to the ERC20 standard? no token
- Are there any novel or unique curve logic or mathematical models? yes
- Does it use a timelock function? yes
- Is it an NFT? no
- Does it have an AMM? no
- Is it a fork of a popular project? true
- If yes, please describe your customisations: Curve VotingEscrow.vy contract translated to solidity and with delegation, quit-lock features added
- Does it use rollups? false
- Is it multi-chain? false
- Does it use a side-chain? false
- Do you have a preferred timezone for communication? CET