Quantstamp performed a security review of the smart contracts implementing the Nemeos protocol based on the code present in the listed repositories. Nemeos offers a buy-now-pay-later service for users willing to buy NFTs from specific collections. The protocol buys NFTs listed in OpenSea using the liquidity provided by other users in a pool associated with that NFT collection. These liquidity providers will get the interest generated by the loan provided to the NFT buyer, based on their share in the pool. The buyer will receive a "wrapped NFT". When the loan is repaid, this NFT is burned, and the borrower receives the real NFT. **Nemeos protocol has a strong dependency on an off-chain oracle that validates and signs all the loan requests. This oracle is out of the scope of this security review. We recommend extensive testing as the smart contracts will assume that every loan request signed is valid. The off-chain systems should follow best practices in private key management. Nemeos team should only interact with well-known and safe NFT collections. Price manipulation can lead to unexpected behavior of the oracle, and therefore affect the protocol.** During the review, some high-severity issues were found. All issues and recommendations are discussed in the *Findings* section of this document. After that, recommendations about documentation are discussed. We strongly recommend addressing all the issues and adding tests to cover the proposed fixes before deployment. The documentation quality is low. It is recommended to add detailed and updated public documentation focusing on the features of the protocol and the potential risks that borrowers and LPs can experience. Regarding testing, all tests passed, but the project does not implement code coverage metrics, failing due to a `StackTooDeep` error. Also, some testing files are in progress (foundry tests). We highly recommend implementing code coverage, improving the branch coverage to a minimum of `95%` and adding new tests to cover the proposed fixes. **Update:** The Nemeos team either provided fixes or acknowledged the issues found during the security review. The acknowledged issues should be revised and taken into account for future iterations of the protocol. We strongly recommend implementing code coverage metrics and finishing the test suite before deployment, as well as designing extensive testing for the off-chain oracle (out of the scope of this security review).
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 9 | 2 | - | - | 11 |
Acknowledged | - | - | - | - | 0 |
Fixed | 4 | 3 | 6 | - | 13 |
| Total | 13 | 5 | 6 | 0 | 24 |
| # | File Name |
|---|---|
| 1 | PoolFactory.sol |
| 2 | SeaportSettlementManager.sol |
| 3 | NFTWrapper.sol |
| 4 | Pool.sol |
| 5 | NFTWrapperFactory.sol |
| 6 | NFTFilter.sol |
| 7 | DutchAuctionLiquidator.sol |