Yield Basis

Ethereum
Audited on 2025/04/25
No open critical findings

Summary

Yield Basis is a decentralized finance system that facilitates leveraged liquidity provision and automated market making (AMM), with a focus on mitigating impermanent loss. Built on Curve's AMM framework, the core innovation is a 2x leverage mechanism that transforms the price behavior of liquidity positions to match that of the underlying tokens, effectively eliminating impermanent loss while preserving fee generation capabilities. The protocol enables an admin to create a Yield Basis market for a specific Curve pool that includes crvUSD and a cryptocurrency, such as WBTC. Users can deposit cryptocurrency into Yield Basis and specify the amount of crvUSD they want the protocol to take on as debt to create a leveraged LP position in the Curve pool. Typically, the debt would be close in value to the deposited cryptocurrency. Once users deposit crypto, they are issued `yb` tokens, representing their share of Curve LP tokens in the Yield Basis protocol. Users can burn their `yb` tokens during a withdrawal to claim the crypto they initially deposited. Holders of `yb` tokens will earn fees from deposits and withdrawals. Optionally, users can stake in `LiquidityGauge`, a simple ERC4626 contract, and earn rewards based on the rate of supplying the LP tokens directly to the Curve pool. Quantstamp was tasked with auditing the Yield Basis contracts to identify potential vulnerabilities and verify that the contracts operate as expected. Specifically, the `AMM`, `CryptopoolLPOracle`, `Factory`, `LT`, and `VirtualPool` contracts were in scope. The `LiquidityGauge` contract and all external contracts, such as the Curve contracts, were considered out of scope. The Yield Basis codebase consisted of Vyper contracts, a technical paper detailing the mechanisms and mathematical equations used in the protocol, and a test suite with moderate coverage. The auditing process for the Yield Basis contracts has revealed several vulnerabilities that need to be addressed to ensure the security and functionality of the protocol. Key vulnerabilities identified include: - Updating the `staker` address does not transfer the staker's balance to the new staker, resulting in incorrect calculations regarding the staked balance of `yb` tokens. - The incomplete integration of flashloan functionality in the `VirtualPool` contract, which lacks critical validations required by ERC3156 and has an inaccessible function, as it is not marked as `external`. - The `LT` contract does not update the staker address correctly after a market is created, which could lead to operational issues if the two contracts are out of sync. <br>The audit team recommends implementing robust validations to enforce safe operations, such as ensuring that addresses passed to critical functions are not zero and applying a two-step ownership transfer pattern for administrative privileges to prevent potential misconfigurations. It is also essential to enhance the test coverage for the `VirtualPool` contract to catch any erroneous functions and to fully document the logic pertaining to functions like `distribute_borrower_fees()`, ensuring their intent and functionality are clear. <br><br><br> **Fix Review:** The Yield Basis team has successfully addressed several vulnerabilities and suggestions in their system at commit `8b05ee9dec073941e7406cf8469e0e11797a436d `. Vulnerabilities YIELD-1 through YIELD-6 are confirmed as fixed. Issues YIELD-7 and YIELD-8 were acknowledged and deemed acceptable as per the client’s design decisions. All auditor suggestions were fixed except for S7, which the client stated is desired behavior. Beyond the fixes for vulnerabilities and suggestions listed in this report, the Yield Basis team made the following changes to the codebase: 1. Added functionality for emergency withdrawals to the `LT` contract. 1. Added functionality in the `AMM` and `LT` contracts to pause and unpause the contracts, altering the ability for users to deposit, withdraw, and swap. 1. The `VirtualPool` contract was updated to include comments indicating that some logic may not yet be implemented. 1. DAO contracts were added to the codebase during the fix review, but remained out of scope.


Issues (8)

Low
Medium
High
Critical
Total
Not fixed
2---2
Acknowledged
----0
Fixed
123-6
Total32308


Contracts (28)