TAC Yieldfi proxy

Ethereum
Audited on 2025/10/13
No open critical findings

Summary

This is an audit of the cross-chain proxy enabling TON Wallet users to interact with the YieldFi lending protocol on TAC/EVM chains via messages sent through the cross-chain layer. The contract inherits from `TacProxyV1Upgradeable`, `UUPSUpgradeable`, and `Ownable2StepUpgradeable`, implementing a smart account abstraction layer that creates individual smart accounts for TON users to execute all ZeroLend interactions. It allows users to `deposit()` and `redeem()` to yieldFi ERC-4626 vaults via a manager intermediary. Where necessary, the manager handles converting the asset provided into the asset of the underlying vault and completes the deposit or redeem action on the underlying vault in a separate future transaction, with any tokens being sent to the user's smart account. After the manager has deposited on behalf of the user, they can call either `claimYToken()` or `claimAsset()` to bridge tokens from their smart account back to the TON chain. The audit of the `YieldManagerProxy.sol` contract has revealed a critical vulnerability that could lead to Denial of Service (DoS) attacks by donating a minimal amount of tokens to prevent legitimate deposits via the `deposit()` function, which enforces a strict balance check requiring the contract’s token balance to match the deposit amount exactly. Furthermore, we suggest input validation improvements to the initialization function, as well as other minor changes to enhance the contract's robustness, such as removing the `payable` modifier from the `deposit()` function, aligning the `claimAsset()` function with other proxies, and eliminating code duplication present in the `claimYToken()` function.


Issues (2)

Low
Medium
High
Critical
Total
Not fixed
----0
Acknowledged
----0
Fixed
1-1-2
Total10102
This project has no active issues.

Contract (1)