Yearn.Finance Security Review

July 24, 2020
Quantstamp Labs

Introduction

Quantstamp completed its informal code review of Yearn Finance. Yearn Finance provides yield-maximizing opportunities for liquidity providers and is intended to be governed in a decentralized manner. Due to the large number of contracts involved in the yEarn system, we limited our review to the most prominent contracts—those that hold funds or can distribute funds. We performed this review as a service to the community. Findings are divided by contract below.

We hope this is useful documentation for community members seeking to understand and improve Yearn. We understand Yearn is a work in progress undergoing rapid iteration, and so is this review; we hope it is helpful.

Overview

The code base for this review was relatively challenging due to the following reasons:

  • The files contain very few code comments, and there was no technical specification available other than posts on Medium or other websites.
  • The Solidity files were flattened by default, and each of them therefore has a copy of common contracts such as SafeMath, ERC20. This complicates computing a diff with the standard implementations of these contracts.
  • The code base did not have any unit, integration, or end-to-end tests. This is concerning as projects lacking tests often have vulnerabilities, especially in edge cases that do not occur on the "happy" code paths.
  • Instances where privileged roles were used to manually distribute protocol fees.

YearnRewards (1st pool) - yCurve LP tokens

Description

The yearn pool stakes yCRV tokens from the Y pool on Curve Finance. The Y pool performs automatic yield-hunting for liquidity providers. It switches liquidity between Aave, Compound, and DyDx to provide the best yield among these platforms. Users of the yearn pool receive YFI tokens.

Source: https://etherscan.io/address/0x0001FB050Fe7312791bF6475b96569D83F695C9f

This contract is a copy of the Synthetix Unipool contract, which was reviewed by Sigma Prime in Feb 2020. Their report can be found here: https://github.com/sigp/public-audits/blob/master/synthetix/unipool/review.pdf.

YearnRewards (2nd pool) - Balancer BPT tokens

Description

Pool #2 stakes pool tokens received when providing liquidity to a Balancer DAI-YFI pool. YFI is distributed to incentivize DAI-YFI liquidity. Users receive YFI tokens for providing this liquidity.

Source: https://etherscan.io/address/0x033E52f513F9B98e129381c6708F9faA2DEE5db5

YearnGovernance (3rd pool) - Balancer BPT tokens

Description

The Governance pool stakes pool tokens received when providing liquidity to a Balancer yCRV-YFI pool. Users receive YFI and, if they stake more than 1000 pool tokens, are eligible to vote on YFI governance proposals.

Source: https://etherscan.io/address/0x3a22df48d84957f907e67f4313e3d43179040d6e#code

Owner and Governance are not multisig-wallet
Severity: High

YearnFeeRewards (4th pool) - stakes YFI for % of protocol fees

Description

The Fee Rewards pool allows users who have staked more than 1000 pool tokens in Pool #3 and voted on a proposal to stake their YFI. By staking YFI, they receive rewards in the form of yCRV tokens.

Source: https://etherscan.io/address/0xb01419E74D8a2abb1bbAD82925b19c36C191A701#code

YFI Contract

Source: https://etherscan.io/address/0x0bc529c00c6401aef6d220be8c6ea1667f6ad93e#code The governance address can add any address as a minter. That minter can mint tokens arbitrarily as there is no cap. Recommendation: Cap value for minting should be decided by governance.

Disclaimer

This informal security review is applicable to the current version of contracts as of July 24, 2020. Quantstamp is aware of the announcement by yearn.finance on its plan to deploy v2 contracts in the next 3-4 days; the v2 contracts are not yet all available and have not been included in this security review.