In this audit, we reviewed the SynFutures token implementation, as well as a staking vault with an upgradability mechanism. The `SynFuturesStakingVault` contract enables users to deposit/stake into the vault and eventually withdraw ("release") their tokens back to their address, after an unstake request and a passed unstake cooldown (`pendingDuration`) of a maximum of 14 days. The deposit, unstake, and release interactions emit events, which will be tracked by an off-chain component. This out of scope off-chain component will then keep track of the user's stake and calculate the corresponding votes enabling an off-chain governance solution. No major issues were identified, except for an incorrect implementation of the upgradability mechanism (SYN-1). The given set of contracts is robust with an excellent test suite. **Update Fix-Review:** All findings have been either fixed or reasonably acknowledged.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 3 | - | - | - | 3 |
Acknowledged | - | - | - | - | 0 |
Fixed | 3 | 1 | - | - | 4 |
| Total | 6 | 1 | 0 | 0 | 7 |
| # | File Name |
|---|---|
| 1 | contracts/proxy/TUProxy.sol |
| 2 | contracts/stake/SynFuturesStakingVault.sol |
| 3 | contracts/SynFuturesToken.sol |