not approved
Yamfore V1 Smart Contract Security Audit I Big Blymp
Current Project Status
Unfunded
Amount
Received
₳0
Amount
Requested
₳180,000
Percentage
Received
0.00%
Solution

We will conduct a thorough audit of Yamfore V1’s smart contracts, identify vulnerabilities, implement fixes, and publicly release the audit report to ensure security and transparency.

Problem

Image file

Yamfore V1 is live on Mainnet. To ensure the highest security, another security audit is needed.

Impact Alignment
Feasibility
Value for money

Team

1 member

Yamfore V1 Smart Contract Security Audit I Big Blymp

Please describe your proposed solution

We propose conducting a comprehensive security audit of Yamfore V1’s smart contracts. With Cardano’s DeFi protocols managing significant amounts of user assets, security is a top priority. As a decentralized pooled lending protocol, Yamfore must be audited to protect user funds and foster trust in the ecosystem.

By engaging a reputable third-party auditing firm, we will ensure that the smart contracts are meticulously reviewed for vulnerabilities and performance improvements. After completing the audit, all necessary fixes will be implemented, and the audit report, along with the open-sourced smart contracts, will be publicly released for transparency.

Please define the positive impact your project will have on the wider Cardano community

The Yamfore V1 Smart Contract audit will enhance the security of decentralized finance (DeFi) on Cardano. By ensuring the safety of user funds, this audit will encourage more users to engage with DeFi, drive liquidity to the platform, and strengthen the overall Cardano ecosystem.

Impact Measurement:

  • Completion of the smart contract audit by a reputable third-party auditing firm.
  • Public release of the audit report and open-source smart contracts.

Sharing Outputs: The audit report, smart contracts, and relevant documentation will be open-sourced on Yamfore’s public GitHub repository. Updates will be shared through Big Blymp’s communication channels, including the website, X, and Discord, ensuring that the Cardano community is informed of the audit’s findings and subsequent improvements.

What is your capability to deliver your project with high levels of trust and accountability? How do you intend to validate if your approach is feasible?

Yamfore is led by a team of experienced blockchain developers with extensive knowledge of Cardano’s architecture, particularly the eUTxO model and Aiken smart contracts. Our team has successfully built and deployed blockchain-based solutions on Cardano.

Yamfore is live on mainnet and the first protocol Audit has been done by TxPipe. (<https://www.yamfore.com/downloads/audit.pdf>)

Capability to Deliver:

Technical Expertise: Our team has a solid foundation in developing secure and efficient smart contracts using Aiken. We have hands-on experience in Cardano’s development environment and are skilled at building complex DeFi solutions.

Processes for Accountability:

Audit Provider: A reputable third-party audit firm with a proven track record in blockchain security will conduct the audit, ensuring the highest standards of professionalism.

Post-Audit Review: After the audit, we will implement all necessary fixes and make the final audit report publicly available to maintain transparency.

What are the key milestones you need to achieve in order to complete your project successfully?

Milestone 1: Audit Firm and Submit Contracts

Timeline: Month 1

Description: Sign the contract with a reputable third-party blockchain auditing firm and submit the Yamfore V1 smart contracts for a full security review.

Acceptance Criteria: Confirmation of the audit engagement and submission of the smart contracts for audit. Initial documentation prepared and submitted to the auditing firm.

Milestone 2: Initial Audit Review and Feedback

Timeline: Month 2

Description: The audit firm conducts a thorough review of the Yamfore V1 smart contracts, identifying any vulnerabilities or performance optimizations. Initial feedback and findings are shared with the development team.

Acceptance Criteria: Receipt of the audit firm’s initial review report outlining any vulnerabilities and recommendations for improvements.

Milestone 3: Implement Fixes and Conduct Final Testing (if needed)

Timeline: Month 3

Description: Based on the audit firm’s feedback, our development team will implement the necessary fixes and optimizations to address any identified vulnerabilities. Final tests will be conducted to ensure that the smart contracts are secure and fully functional.

Acceptance Criteria: Confirmation that all critical vulnerabilities have been addressed and the smart contracts pass final tests for security and functionality.

Milestone 4: Publish Final Audit Report and Open Source Smart Contracts

Timeline: Month 3

Description: The final audit report will be released publicly, and the fully-audited Yamfore V1 smart contracts will be made open-source on a public GitHub repository.

Acceptance Criteria: Public release of the audit report, smart contracts, and supporting documentation on Yamfore’s GitHub.

Final Milestone: Project Close-Out Report

Timeline: End of Month 4

Description: We will create and release a comprehensive project close-out report summarizing the audit process, results, and the overall impact on the Yamfore protocol and the wider Cardano community.

Acceptance Criteria: Completion and publication of the project close-out report, shared on Yamfore’s website and through Cardano community channels.

Who is in the project team and what are their roles?

Brandon Chukwuka

Role: Lead Project Manager - Big Blymp Founder

Responsibilities: Overseeing the project, managing timelines, coordinating development, and ensuring milestones are met.

X: zartsnarf

Diego Macchi

Diego Macchi is a graduate from the Economic University of Buenos Aires. Cardano OG and member of de DeFi community.

Role: Community Advisor

Responsibilities: Community advisor and partnerships lead.

X: diegomac35

Dominic Wallis (Waalge)

Waalge is Math PhD. Formerly ML engineer and full-stack dev. DApp developer since Alonzo HF. Aiken contributor, particularly the nix maintenance and fuzz lib.

Role: Smart Contract Developer

Responsibilities: Developing the core Aiken smart contracts and ensuring the protocol’s security and functionality.

Developing the user interface for interacting with the lending pools, managing deposits, and yield visualization.

X: Waalge

GitHub: <https://github.com/waalge>

Jimmy

Role: Front End Developer

Responsibilities: Developing the front end smart contracts

<https://0xjimmy.xyz/>

X: 0xjimmy_eth

GitHub: <https://github.com/0xjimmy>

Gritar

Role: Graphic Designer

Responsibilities: design the user interface for interacting with the lending pools, managing deposits, and yield visualization.

X <span class="mention" data-denotation-char="" data-id="148275" data-index="0" data-value="<member id='41356' communityId='163'>gritar</member>"><span contenteditable="false"><span class="ql-mention-denotation-char"></span><member communityid="163" id="41356">gritar</member></span></span>

Linda - MALU Pool

Role: Marketing and communications

Responsibilities: Video content creation and educational resources.

X: Cryptofly777

Please provide a cost breakdown of the proposed work and resources

1- External Audit Firm:

Cost: 100,000 ADA

Description: Covers the cost of hiring a reputable third-party audit firm to conduct a comprehensive audit of Yamfore V1’s smart contracts.

2- Smart Contract Development and Bug Fixes:

Cost: 50,000 ADA

Description: Covers development work for implementing fixes and conducting final tests after the audit.

3- Project Management and Coordination:

Cost: 15,000 ADA

Description: Covers the costs of overseeing the project, coordinating with the audit firm, and ensuring timely delivery of milestones.

4-Documentation and Reporting:

Cost: 15,000 ADA

Description: Creation of comprehensive documentation.

Total Project Cost:

180,000 ADA

No dependencies.

How does the cost of the project represent value for money for the Cardano ecosystem?

The cost of this project represents excellent value for the Cardano ecosystem by ensuring the security and transparency of Yamfore, a key DeFi protocol. A thorough security audit is essential to safeguard user funds and prevent potential vulnerabilities. The budget is proportional to the high standards expected in the blockchain industry, particularly for DeFi protocols managing significant funds.

The audit cost aligns with industry standards for complex DeFi projects. Security audits are critical to preventing exploits, and this investment ensures that Yamfore will meet the highest security standards.The developer rates are competitive for blockchain professionals and necessary to ensure that the smart contracts are secure and optimized.

By funding this project, the Cardano community is investing in a secure, open-source DeFi protocol, which will boost user confidence, liquidity, and developer engagement within the ecosystem.

close

Playlist

  • EP2: epoch_length

    Authored by: Darlington Kofa

    3m 24s
    Darlington Kofa
  • EP1: 'd' parameter

    Authored by: Darlington Kofa

    4m 3s
    Darlington Kofa
  • EP3: key_deposit

    Authored by: Darlington Kofa

    3m 48s
    Darlington Kofa
  • EP4: epoch_no

    Authored by: Darlington Kofa

    2m 16s
    Darlington Kofa
  • EP5: max_block_size

    Authored by: Darlington Kofa

    3m 14s
    Darlington Kofa
  • EP6: pool_deposit

    Authored by: Darlington Kofa

    3m 19s
    Darlington Kofa
  • EP7: max_tx_size

    Authored by: Darlington Kofa

    4m 59s
    Darlington Kofa
0:00
/
~0:00