Impossible Finance

Multi-Chain
Audited on 2024/03/15
Rekt reported

Summary

This audit focuses on the functionality of the launchpad token sale, where the funder can set the price of the token and users can purchase the token based on their allocations, which is verified through the use of a Merkle proof. A user can then withdraw the purchased tokens in the future that might be subjected to a vesting or cliff schedule. In some cases, there can be giveaway sales where users can withdraw a set amount of sale tokens without purchasing any with an optional whitelist feature via Merkle proofs. Quantstamp conducted the audit with three auditors. This audit only concerns the changes in the following files `IFFixedSale.sol`, along with a review of the inherited contracts, namely `IFSale.sol`, `IFPurchasable.sol`, `IFFundable.sol`, `IFVestable.sol`, and `IFWhitelistable.sol`. The code is straightforward and generally well-written, supported by relatively robust test cases. However, the extensive use of inheritance introduces unnecessary complexity, especially concerning the review of permissions (or lack of) for the overridden functions. Our team identified two high-severity issues involving giveaway sales (IF-1), allowing users to obtain unlimited giveaway amounts when the whitelist is not set, and the accounting of sale tokens in whitelisted purchases with referral codes (IF-2). The test suites have acceptable line coverage (~62%), but we would recommend the team improve the test suites further, especially with regard to branch coverage, which is currently at around 42%. **Update**: The client has either fixed or acknowledged all the issues in this report. Furthermore, the team also added a few new test cases as part of the fixes (i.e. from 64 to 69 test cases). In the latest commit, the team also introduced a new feature where users may only purchase an integer amount of sale tokens.


Issues (13)

Low
Medium
High
Critical
Total
Not fixed
5---5
Acknowledged
----0
Fixed
611-8
Total1111013


Contracts (6)