Lido – Security Review of Oracle V5 update
Lido partnered with Composable Security to conduct a thorough security review of the Oracle V5 update to prepare for upcoming Pectra hard fork. Basic […]
The main objective was verification of the security of smart contracts and identification of threats occurring at the edge of integration with web2 components.
Project type: Funding model for researchers.
Service: Smart contract security review.
Results: Our service helped detect and prevent kill-chain with a critical impact on Research Portfolio security and improved the overall security of their DApp.
Cinjon Resnick (Founder of Research Portfolio) contacted us through the recommendation of one of our friends at the beginning of August.
Research Portfolio builds tools for researchers to mint and trade tokens representing their research output. A two-person team works on the creation of a funding model where not only scientific work is rewarded, but also people’s contribution to its creation.
The launch was scheduled for September alongside the Amaranth Prize. Until then, Cinjon wanted to make sure their contracts were secure and would allow users to use the solution safely.
Visit website: https://www.researchportfolio.co/
The subjects of the test were selected contracts from the Research Portfolio repository.
GitHub repository: https://github.com/researchportfolio/researchportfolio
CommitID: ed40cada20b7e07519be4606e8b33dccf05124ae
As before every smart contract audit, thorough threat modeling is performed. The results are made available to the client for joint analysis.
The following attacker goals were identified as the most important:
A few examples of threat scenarios that allow for risking or compromising the security of identified key assets:
More can be found in the report.
22 identified threats turned out to be present in the project. The smart contract audit performed allowed for the detection of vulnerabilities related to business logic and architecture design.
Thanks to the work of the Research Portfolio team, 18 issues were removed. Additionally, a critical vulnerability that was found outside the scope of the service has been removed.
Let’s engage in a conversation. Share details about your current security strategies and measures. This will enable us to provide professional advice on potential enhancements and additional actions that could be beneficial for your security framework.
Composable Security 🇵🇱⛓️ is a small team with a holistic approach that goes beyond the code. A combination of expertize in Solidity smart contract security and experience gained through 6+ years securing global fintechs and Polish banks help comprehensively take care of DApp security. Learn more about us.
Creators of the Smart Contract Security Verification Standard and the first Security Guide for DApps CTOs, Lead Developers, and Security Enthusiasts.
Meet Composable Security
Get throughly tested by the creators of Smart Contract Security Verification Standard
Let us help
Get throughly tested by the creators of Smart Contract Security Verification Standard