Back to Overview

Frankencoin FPS2

Quotation mark icon

The audit was excellent! Very well done! I'm impressed with how quickly ChainSecurity's engineers developed a deep understanding of the Frankencoin system and with their meaningful inputs to harden its mechanics.

Luzius Meisser
Inspirer

About Frankencoin FPS2

Frankencoin implements FPS2, a wrapper that holds existing Frankencoin Pool Share tokens (FPS) one to one and adds a revised, binding governance layer on top, functioning as a shareholder agreement among participating FPS holders. Once more than two thirds of all FPS voting power has been wrapped into FPS2, the governance layer becomes binding and FPS2 holders gain the ability to permanently disempower FPS holders that have not joined. FPS2 implements the ERC-4626 interface with ZCHF as the underlying asset. A set of governance modules synchronizes FPS2 voting power to sidechains via CCIP, enabling cross-chain vetoes.


Audit Summary

The most critical subjects covered in our audit are the integrity of the binding governance transition and the underlying vote accounting. The governance transition mechanism has been fixed by addressing Shoot Enables Governance Takeover and Unlimited Minting. The wrapping design was improved to address Free Wrap/unwrap Round-Trips Can Delay FPS2 Binding Forever. Security regarding the aforementioned subjects is now high.

Beyond the binding mechanism, we covered the cross-chain deployment of the governance modules and conformance with the ERC-4626 standard. We reviewed the ERC-4626 interface thoroughly, and found that several view and mutator functions deviate from the standard's requirements, see ERC-4626 Spec Violations in FPS2MintRedeem and FPS2MintRedeem Mishandles Vault-Specific Limits, Violating ERC-4626. After resolving these issues, compliance with 4626 spec is now good.

The general subjects covered are code quality, documentation, and functional correctness.

In summary, we find that the codebase provides a high level of security.

It is important to note that security audits are time-boxed and cannot uncover all vulnerabilities. They complement but don't replace other vital measures to secure a project.