This audit focused on the Origin platform for the Camp Network. The Camp Network is an EVM-compatible layer-1 blockchain focused on intellectual property (IP) registration and monetizing its use by AI agents. The Origin platform plays a key role in this by providing users with functionality to: - Register IP onchain - Sell the right to access this IP - Dispute potential fraudulent or stolen IP The protocol achieves this through three core contracts, the `IpToken`, the `Marketplace`, and the `DisputeModule`. **IpToken** The `IpToken` contract allows users with a valid signature from an authorized `signer` to mint an ERC-721 token representing their IP via the `mintWithSignature()` function. The user can set their own licensing terms, including: - The subscription fee to use the IP - The subscription duration - The payment token that is required - The required royalties if other registered IP is a derivative of this IP. **Marketplace** The `Marketplace` contract allows users to purchase access to registered IP via the `buyAccess()` function. This function handles paying the creator fee to the IP owner as well as sending royalties to any of the IP's parent IP. **DisputeModule** The `DisputeModule` contract allows users to dispute potential infringed or fraudulent IP. The dispute process works as follows: 1. A user believing an IP is fraudulent can call the `raiseDispute()` function, providing both a hash of the evidence for their claim and a `disputeBond` in `wCAMP` tokens to disincentivise false claims. 2. Until the IP owner provides evidence, the original claimant can call `cancelDispute()` to withdraw their initial dispute claim. 3. The owner of the IP will have a window to provide counter evidence by calling the `disputeAssertion()` function. 4. After this window has closed, the protocol owner makes a judgment on the claim via the `setDisputeJudgement()` function. If the dispute is successful, the original claimant's `disputeBond` is returned and the IP is marked as `DISPUTED`, limiting any further access to this IP. However, if the dispute is unsuccessful, the claimant's `disputeBond` is split between the contract owner and the owner of the IP. <br /> During the audit, we have identified various exploits that leverage frontrunning by monitoring the mempool and submitting malicious transactions to change the state of the ledger before interactions from other users are executed. This can be used to change the terms before access is bought in the marketplace (CAMP-3), block dispute evidence in the dispute module (CAMP-2), or maximize the royalties for derivative tokens (CAMP-5). The protocol avoids DoS of payment recipients by creating vaults for token holders. Critically, in some cases, vaults may be missing, leading to a loss of transferred funds (CAMP-1). Multiple other issues are caused by lacking or imprecise input validations. A minor concern is the dispute propagation mechanism from parent to derivative child tokens, which is limited by the cooldown period in its current form (CAMP-12). Overall, addressing these vulnerabilities with the suggested recommendations is crucial to enhancing the security and usability of the platform. The code quality could be improved, but the documentation is helpful, and the test suite has good coverage. **Update fix review:** The submitted fixes successfully addressed all issues apart from CAMP-3, which has been acknowledged in favor of avoiding duplicate evidence hashes. Similarly, input validation concerns outlined in S-6 have been acknowledged and earmarked for potential future improvements. Many suggestions have been addressed as suggested, whereas some remain unresolved, including missing event emissions in the marketplace and a potential refactoring of the payment routing to avoid code duplication. Generally, it should be noted that the Camp network is not fully vulnerable to frontrunning exploits due to a private mempool, but related issues remain significant to avoid accidental or speculative occurrences.
Low | Medium | High | Critical | Total | |
|---|---|---|---|---|---|
Not fixed | 1 | 1 | - | - | 2 |
Acknowledged | - | - | - | - | 0 |
Fixed | 6 | 2 | 2 | - | 10 |
| Total | 7 | 3 | 2 | 0 | 12 |
| # | File Name |
|---|---|
| 1 | Scope not recorded here: see the report |