Executive Summary

From July 1, 2024, to Aug 1, 2024, the IXO project engaged Fuzzland to conduct a thorough security audit of their IXO Protocol V1 project. The primary objective was to identify and mitigate potential security vulnerabilities, risks, and coding issues to enhance the project's robustness and reliability. Fuzzland conducted this assessment over 90 person-days, involving 3 engineers who reviewed the code over a span of 30 days. Employing a multifaceted approach that included static analysis, fuzz testing, and manual code review, Fuzzland team identified 23 issues across different severity levels and categories.

Scope

Project Name IXO Protocol V1
Repository Link
Commit
Fix Commit
Language Solidity - Ethereum
Scope contracts/**/*.sol

Disclaimer

The audit does not ensure that it has identified every security issue in the smart contracts, and it should not be seen as a confirmation that there are no more vulnerabilities. The audit is not exhaustive, and we recommend further independent audits and setting up a public bug bounty program for enhanced security verification of the smart contracts. Additionally, this report should not be interpreted as personal financial advice or recommendations.

Auditing Process

Vulnerability Severity

We divide severity into four distinct levels: high, medium, low, and info. This classification helps prioritize the issues identified during the audit based on their potential impact and urgency.