not approved

FluidTokens Protocol Security Audit

$100,000.00 Requested
Ideascale logo View on ideascale
Community Review Results (1 reviewers)
Impact / Alignment
Feasibility
Auditability
Solution

Our focus at the moment is to implement code review for FluidTokens smart contracts and audit them to release the latest version as open source

Problem:

FluidTokens is the first open Decentralized Lending platform that allows anyone to request ADA using his/her NFTs or tokens. Aditing the v2 of the Smart Contract is important to protect the community

Yes Votes:
₳ 3,296,456
No Votes:
₳ 26,914,399
Votes Cast:
159

  • download
  • download

[IMPACT] Please describe your proposed solution.

At the current state of the art it is important to audit the smart contracts created by our internal team with an external partner:

Team experience:

Canonical Experience:

In collaboration with Canonical the smart contracts created by FluidTokens team will be assessed and reviewed to avoid any possible exploit considering how new lending and borrowing is in Cardano

[IMPACT] What are the main risks that could prevent you from delivering the project successfully and please explain how you will mitigate each risk?

Risks are:

  • Exploits that are not found during the auditing part but are found after open sourcing the platform

Solutions:

  • We have a lag release of opensource of the code, the current version of the platform is an improved version of the opensource one, in this way any malicious attacker cannot attack the current platform

    [FEASIBILITY] Please provide a detailed plan, including timeline and key milestones for delivering your proposal.

  • September 2022 starting the audit of current smart contract and new smart contract version

  • October 2022 final code review with our tech partners

  • November 2022 opensource of the code after finalizing the audit stage

    [FEASIBILITY] Please provide a detailed budget breakdown.

Considering the amount of hours for the auditing:

  • QA 100 hours
  • Testing 50 hours
  • Code Review 200 hours
  • Code fixing 50 hours

The cost of engineer and plutus developers in order to provide the audit is $90000, considering $10000 in case of extra costs

[FEASIBILITY] Please provide details of the people who will work on the project.

Even if FluidTokens is already scaling and it is strongly appreciated by the Cardano community, the costs of a widely accepted auditing are high for a recently created platform. In the next months, for any complex smart contract we're going to release, we'll probably need additional funds to audit them

[AUDITABILITY] Please describe what you will measure to track your project's progress, and how will you measure these?

Team will release monthly updates on the current state of the development in order to be trasparent and open

[AUDITABILITY] What does success for this project look like?

The success is not defined by a complete absence of bugs (which can never be guaranteed) but to ensure the absence of any known attack vector and the use of the most accepted best practices when writing smart contracts. Transparency with the Cardano community is also a must.

[AUDITABILITY] Please provide information on whether this proposal is a continuation of a previously funded project in Catalyst or an entirely new one.

It is not

Community Reviews (1)

Comments

close

Playlist

  • EP2: epoch_length

    Authored by: Darlington Kofa

    d. 3 se. 24
    Darlington Kofa
  • EP1: 'd' parameter

    Authored by: Darlington Kofa

    d. 4 se. 3
    Darlington Kofa
  • EP3: key_deposit

    Authored by: Darlington Kofa

    d. 3 se. 48
    Darlington Kofa
  • EP4: epoch_no

    Authored by: Darlington Kofa

    d. 2 se. 16
    Darlington Kofa
  • EP5: max_block_size

    Authored by: Darlington Kofa

    d. 3 se. 14
    Darlington Kofa
  • EP6: pool_deposit

    Authored by: Darlington Kofa

    d. 3 se. 19
    Darlington Kofa
  • EP7: max_tx_size

    Authored by: Darlington Kofa

    d. 4 se. 59
    Darlington Kofa
0:00
/
~0:00