TronGuru AUDIT
Address TRON Main Network: TVBTm8UDC3SHXaymtAVFkjo5L1apLATpE5
Conclusion:
In the TronGuru Smart-Contract were found no vulnerabilities and no backdoors. The code was manually reviewed for all commonly known and more specific vulnerabilities.
So TronGuru Smart-Contract is safe for use in the main network.
CRITICAL ISSUES (critical, high severity): 0
Bugs and vulnerabilities that enable theft of funds, lock access to funds without possibility to restore it, or lead to any other loss of funds to be transferred to any party; high priority unacceptable bugs for deployment at mainnet; critical warnings for owners, customers or investors.
ERRORS, BUGS AND WARNINGS (medium, low severity): 0
Bugs that can trigger a contract failure, with further recovery only possible through manual modification of the contract state or contract replacement altogether; Lack of necessary security precautions; other warnings for owners and users.
OPTIMIZATION POSSIBILITIES (very low severity): 1
Possibilities to decrease cost of transactions and data storage of Smart-Contracts.
NOTES AND RECOMMENDATIONS (very low severity): 2
Tips and tricks, all other issues and recommendations, as well as errors that do not affect the functionality of the Smart-Contract.
AUDIT RESULT:
Optimization possibilities
1. Recording statistical parameters in the blockchain (very low severity):
List of statistical parameters that also increase the cost of transactions and increase the amount of data stored in the blockchain:
uint256 public TotalInvestors;
uint256 public TotalInvested;
uint256 public TotalWithdrawn;
uint256 public TotalDepositCount;
Commissions[] commissions;
uint256 totalInvested;
uint256 totalWithdrawn;
uint256 totalCommisions;
uint256 lvlonecommisions;
uint256 lvltwocommisions;
uint256 lvlthreecommisions;
Recommendation: use events and log this information instead of writing it to the blockchain.
Note: some use of this variables could be avoided at all, like totalCommisions, lvlonecommisions, lvltwocommisions, lvlthreecommisions because array of structs commissions used to save all info anyway.
Note: this comment doesn’t affect the main functionality of the smart-contract.
Notes
2. Loops on parallel deposits (very low severity):
In the WithdrawDividends, GetUserDividends functions, cycles unrestrictedly grow as the number of deposits increases. If you create a large number of parallel deposits from a single wallet, this can lead to an excessive increase in the transaction cost and incorrect display and processing of information.
Note: this comment is only relevant for a certain user, if he creates an excessive number of deposits (more than 300) from his wallet.
3. Closing the last payment (very low risk).
If the last user who leaves the project has a payout greater than the smart-contract balance, he will receive the entire available balance, but it will be recorded that the entire payout was closed.
Note: this comment is not critical, since after the smart contract balance is empty, it is unlikely that the contract will be used again. So it makes sense for last user to get at least something.
Independent description of the smart-contract functionality:
The TronGurucontract provides the opportunity to invest any amount in TRX (from 100
TRX) in the contract and get a 150% return on investment, if the contract balance has enough funds for payment.
Dividends are payed from deposits of users (Ponzi scheme).
You can create a Deposit by calling the “invest” function and attaching the required amount of TRX to the transaction (from 100 TRX inclusive).
Each subsequent Deposit is kept separately in the contract, in order to maintain the payment amount for each Deposit.
The percentage charged to the user starts from 2% and depends on the following factors:
— For every 1,000,000 TRX on the smart contract balance +0.01% untill 1%.
— For every 1 day of non-withdrawal of dividends from the smart contract +0.01% untill 1% (when creating repeated deposits, the percent keeps growing).
Also the Hold Bonus is not reset to 0 if user withdraws when deposit is fully payed
(150% is reached).
Withdrawals of dividends are available at any time. Withdrawal by the use is performed by callin the “WithdrawDividends” function from the address the Deposit was made.
All dividends are calculated at the moment of request and available for withdrawal at any time.
Contract owners Commission: part of the invested funds is sent to two addresses:
(marketing address) — 8%.
(the project address) – 3%.
Three-level referral program: in the “invest” function, you can specify the address of the referrer. As a result, the referrer will get opportunity to withdraw % of the investor’s Deposit according to the following table:
Referrer level | 1 | 2 | 3 |
Percentage, % | 5 | 3 | 1 |
Requirements for the referrer: you can not specify your own wallet as a referrer, as well as a wallet that does not have at least one contribution in the smart contract. If wrong referrer is provided, no referrer will be set.
The referrer is specified once at the time of any deposit and is assigned to the user without the possibility of changing. From each subsequent Deposit, the referrer will get his percents.
Referral bonuses can be withdrawn separately from dividends using
WithdrawCommissions function. Hold Bonus will not be losed.
The contract contains 16 statistical functions that do not require sending transactions:
1. GetContractBalance– smart contract balance (with decimals, for TRX – 6
characters).
2. CurrentBonus – the current percentage for a new user.
3. GetHoldBonus – the current Hold Bonus for the specified user.
4. GetUserDividends – the current amount of dividends available to withdraw.
5. GetTotalCommission – the amount of received referral commissions
6. GetUserTotalDeposits – the amount of user’s deposits.
7. getUserDepositInfo – amount, withdrawn value and UNIX start date of the deposit.
8. GetUserData — user info: upline, total invested amount, total withdrawn amount, total comissions, level commissions. available commission and UNIX date of the last withdrawal (checkpoint).
9. GetUserCommission — commission info by specified index
10. TotalInvestors – the number of investors.
11. TotalInvested – the sum of each deposits of the all users.
12. TotalWithdrawn – users withdrawal amount.
13. TotalDepositCount — amounts of deposits of all users
14. ActiveClient — return ‘true’ if user got not payed deposit.
Disclaimer
This audit is not a call to participate in the project and applies only to the Smart-Contract code at the specified address.
Do not forget that you are doing all financial actions at your own risk, especially if you deal with high-risk projects.
If you have any questions or are interested in developing/auditing of Smart-Contracts, please contact us and we will consult you.
Telegram: @gafagilm
E-mail: info@grox.solutions