/2021-09-wildcredit

CodeArena audit repo

Primary LanguageSolidity

Wild Credit contest details

wild.credit@WildCredit@0xdev0discordGitBook

Contest scoping

Wild Credit is a lending protocol. Unlike Compound or Aave, which are composed of a "basket" of approved tokens, Wild Credit instead has isolated lending pairs. Similar to Uniswap, each pair does not influence the state of any other pair in any way. This allows much better risk management and allows the protocol to list less liquid tokens.

Both tokens in each lending pair can be used either as collateral or the borrowed token. To borrow one token, the borrower must deposit the other token as collateral. Each account can only borrow one of the tokens at the same time. To borrow the other token, the currently borrowed token must be repaid in full and the collateral must be withdrawn. A lender may deposit both tokens at the same time to earn interest.

Borrowers are also able to use their Uniswap V3 positions as collateral.

Please review all contracts in this repository. Special interest could be given to positionAmounts() function inside of UniswapV3Helper.sol which is used to determine USD value of a position. Another potential source of bugs could be token conversions inside of LendingPair.sol. There are a lot of functions accepting tokenA, tokenB, priceA, priceB, converting amounts to shares, shares to amounts, etc.

The old version of the protocol can be seen here http://wild.credit/ Note that this UI should only be used to get a basic conceptual understanding of how the protocol works. It uses an old version of contracts which do not support Uniswap V3 positions.

ERC20 difference: LPTokenMaster.sol outsources balance tracking & manipulations to the LendingPair. Since most balance manipulations are likely to be related to lending and not transfers, this change was made to save gas by reducing external calls from the LendingPair.

Please disregard anything currently deployed on mainnet. Subject to review is only the code in this repo and nothing else.

External calls are made by the oracles - Chainlink and Uniswap V3 oracles.

Docs (old version): https://wild-credit.gitbook.io/wild-credit/