Mars4 Shoot ERC-20 Security Review

Ethereum
Audited on 2024/04/12
No open critical findings

Summary

Quantstamp conducted a security review for the `ShootERC20` token developed in the Mars Battle project. The `ShootERC20` token slightly modifies the ERC-20 standard contract written by OpenZeppelin. Upon creation, the `ShootERC20` contract mints a fixed number of `1_000_000_000` tokens to the contract deployer. The `ShootERC20` holders can transfer or approve another address to transfer their tokens, the same as a typical ERC-20 token. Additionally, the `ShootERC20` holders can burn an arbitrary number of their tokens up to their entire balance. As there is no further minting of the token after the contract creation, the total supply of `ShootERC20` can only decrease through time when a user burns their token. All issues included in this report are informational in severity. MS-1 and MS-2 point out this project needs more documentation and tests. MS-3 points out a best practice of smart contract development. MS-4 describes a well-known issue of ERC-20 tokens, and MS-5 describes a concern about locked funds in the contract. Although the additions to the base ERC-20 contract are minimal, the project has no tests, so the changes are not covered. Quantstamp, as always, strongly recommends adding tests to safeguard against unpredictable code. All issues in this report are considered acknowledged.


Issues (5)

Low
Medium
High
Critical
Total
Not fixed
5---5
Acknowledged
----0
Fixed
----0
Total50005


Contract (1)