Skip to content

Royco | Ethereum | available#139

Draft
yvesbou wants to merge 2 commits intomainfrom
royco
Draft

Royco | Ethereum | available#139
yvesbou wants to merge 2 commits intomainfrom
royco

Conversation

@yvesbou
Copy link
Collaborator

@yvesbou yvesbou commented Apr 15, 2025

No description provided.

@vercel
Copy link

vercel bot commented Apr 15, 2025

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Comments Updated (UTC)
defiscan ✅ Ready (Inspect) Visit Preview 💬 Add feedback Jun 3, 2025 6:41am

@yvesbou yvesbou added the $1000 label Apr 15, 2025
@alexandre-mrt
Copy link

Hey @yvesbou ,
I will take that case, should be finished end of next week.

@yvesbou
Copy link
Collaborator Author

yvesbou commented Apr 16, 2025

@alexandre-mrt thank you for your interest in DeFi Scan and writing a report! We're looking forward to your findings.

@yvesbou yvesbou changed the title Royco | Ethereum | [available] Royco | Ethereum | [30.04.2025] Apr 16, 2025
@emduc
Copy link
Member

emduc commented Apr 22, 2025

Hi @alexandre-mrt, Thanks for taking on this review

Here you can find an excalidraw where you can make a diagram of the protocol that could be included in the review. We try to have diagrams to show and explain the contract interactions in every new review. You can have a look at compound-v3 as an example.

https://link.excalidraw.com/l/9pt8PDVB43r/boUxLaHuDl

@yvesbou yvesbou changed the title Royco | Ethereum | [30.04.2025] Royco | Ethereum | [19.05.2025] May 5, 2025
@yvesbou
Copy link
Collaborator Author

yvesbou commented May 6, 2025

hey @alexandre-mrt how are you doing with the report? do you need some help?

@yvesbou
Copy link
Collaborator Author

yvesbou commented May 19, 2025

please submit a draft (does not have to be 100%) by Thursday otherwise we mark this as available @alexandre-mrt

@yvesbou yvesbou changed the title Royco | Ethereum | [19.05.2025] Royco | Ethereum | available May 27, 2025
@Aabdullahi015
Copy link

I'm interested in writing this review. I'd love to contribute to Defiscan, too!

@yvesbou
Copy link
Collaborator Author

yvesbou commented Jun 3, 2025

sure thing @Aabdullahi015

You have two weeks time to submit a first draft (until 18.06).
If you have questions, we cant stress enough that all questions are encouraged!

I've updated the template to the latest version just now. Go through the contracts table, run them with the permission scanner. Fill out the permission table with the functions that are restricted/permissioned. While doing that, figure out the smart contract architecture, draw a diagram showing key user interactions + permissioned function calls. This should help contextualise the report and the mentioned contracts and permissions.

The ratings section should name concrete centralization vectors (upgrading, stealing funds, withholding fees/incentives etc.). The protocol analysis section should explain the diagram(s) and can be more technical, mention concrete functions etc.

The permission table (contract | function | impact | owner) should also be technical.

Regarding autonomy/dependency, this is for assessing the risk of dependencies that could break and what's the effect on the studied defi protocol (in this case euler v2). Dependencies are strictly outside, so a multisig of the team is not considered for the category of dependency. For a borrow lending platform, price oracles are the obvious dependency that have centralizing effect on their autonomy

Generally, when speaking about risk:

high risk -> users can suffer loss of deposited funds
medium risk -> users can suffer loss of unclaimed yield or temporary loss of funds
low risk -> users are confronted with drastic performance changes, like excessive fees etc.

all these risks are induced through
either malicious/faulty upgrade or dependency failure/manipulation

@yvesbou yvesbou changed the title Royco | Ethereum | available Royco | Ethereum | 18.06.2024 Jun 4, 2025
@yvesbou
Copy link
Collaborator Author

yvesbou commented Jun 17, 2025

Hi @Aabdullahi015 mind the deadline is tomorrow. Can you please report on the progress?

@Aabdullahi015
Copy link

I apologize for missing the deadline — I encountered technical issues with my permission scanner setup that necessitated reinstalling my operating system due to Python dependency conflicts. I’m still refining the draft to ensure it meets DefiScan’s standards. I respectfully request a four-day extension to submit a complete and high-quality review.

@yvesbou
Copy link
Collaborator Author

yvesbou commented Jun 23, 2025

Hi @Aabdullahi015
Can you show us your work in progress?

@yvesbou yvesbou changed the title Royco | Ethereum | 18.06.2024 Royco | Ethereum | available Jul 2, 2025
@yvesbou
Copy link
Collaborator Author

yvesbou commented Jul 2, 2025

This bounty is available again.

@eliasbourgon
Copy link
Contributor

Hi,
I’d be happy to take on this review.

@yvesbou
Copy link
Collaborator Author

yvesbou commented Aug 4, 2025

@eliasbourgon please take sth else - I just checked and it seems that the TVL of royco completely collapsed, so royco is not justified for a bounty anymore

@eliasbourgon
Copy link
Contributor

ok thanks, is there something else ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants