The current report is concerning an audit performed on the SynFutures@V3 protocol, which provides a market for users to trade both perpetual and dated futures. Market makers are able to provide liquidity using both limit orders and ranges; both traders and market makers are able to use leverage in order to open their positions. Price data is sourced from resources such as Chainlink and Uniswap V2-style markets, and the price that governs trading activity is mandated to remain within a range around the price from the resource. Users are also incentivized via a tipping mechanism to liquidate positions and fill limit orders as they are taken by traders. Overall, we found the code quality of the project to be very high. One issue, SYN-1, stood out as particularly noteworthy as it lays out a means by which the protocol may unintentionally benefit a class of sophisticated actors at the expense of retail users. This attack uses user activity to generate a risk-free profit for the sophisticated actors. A specification was provided for the audit; however, it may be significantly improved by using writing that is more concise and organized. It would also have been more helpful to receive it in the form of functional requirements rather than what appeared to be an extension of the whitepaper. We noted following review of the test suite that its quality was remarkable; however, we were unable to retrieve coverage data. **Update**: All of the issues have been addressed. Note that where some issues were determined by the SynFutures team to be "Fixed", we have determined that in fact they were "Mitigated". Also, we discovered a new issue (SYN-23). We recommend that this issue be addressed as well.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 10 | 2 | 1 | - | 13 |
Acknowledged | - | - | - | - | 0 |
Fixed | 9 | 1 | - | - | 10 |
| Total | 19 | 3 | 1 | 0 | 23 |
| # | File Name |
|---|---|
| 1 | contracts/libraries/*.sol |
| 2 | contracts/*.sol |
| 3 | contracts/interfaces/*.sol |