Last updated 4 months ago
Yamfore V1 is live on Mainnet. To ensure the highest security, another security audit is needed.
This is the total amount allocated to Yamfore V1 Smart Contract Security Audit I Big Blymp.
We will conduct a thorough audit of Yamfore V1’s smart contracts, identify vulnerabilities, implement fixes, and publicly release the audit report to ensure security and transparency.
No dependencies.
The Yamfore V1 smart contracts and all relevant project outputs will be fully open-source throughout the project lifecycle. The code, audit reports, and accompanying documentation will be available in a public GitHub repository, promoting transparency and security within the Cardano ecosystem.
We propose conducting a comprehensive security audit of Yamfore V1’s smart contracts. With Cardano’s DeFi protocols managing significant amounts of user assets, security is a top priority. As a decentralized pooled lending protocol, Yamfore must be audited to protect user funds and foster trust in the ecosystem.
By engaging a reputable third-party auditing firm, we will ensure that the smart contracts are meticulously reviewed for vulnerabilities and performance improvements. After completing the audit, all necessary fixes will be implemented, and the audit report, along with the open-sourced smart contracts, will be publicly released for transparency.
The Yamfore V1 Smart Contract audit will enhance the security of decentralized finance (DeFi) on Cardano. By ensuring the safety of user funds, this audit will encourage more users to engage with DeFi, drive liquidity to the platform, and strengthen the overall Cardano ecosystem.
Impact Measurement:
Sharing Outputs: The audit report, smart contracts, and relevant documentation will be open-sourced on Yamfore’s public GitHub repository. Updates will be shared through Big Blymp’s communication channels, including the website, X, and Discord, ensuring that the Cardano community is informed of the audit’s findings and subsequent improvements.
Yamfore is led by a team of experienced blockchain developers with extensive knowledge of Cardano’s architecture, particularly the eUTxO model and Aiken smart contracts. Our team has successfully built and deployed blockchain-based solutions on Cardano.
Yamfore is live on mainnet and the first protocol Audit has been done by TxPipe. (https://www.yamfore.com/downloads/audit.pdf)
Capability to Deliver:
Technical Expertise: Our team has a solid foundation in developing secure and efficient smart contracts using Aiken. We have hands-on experience in Cardano’s development environment and are skilled at building complex DeFi solutions.
Processes for Accountability:
Audit Provider: A reputable third-party audit firm with a proven track record in blockchain security will conduct the audit, ensuring the highest standards of professionalism.
Post-Audit Review: After the audit, we will implement all necessary fixes and make the final audit report publicly available to maintain transparency.
Audit Firm and Submit Contracts
Timeline: Month 1
Description: Sign the contract with a reputable third-party blockchain auditing firm and submit the Yamfore V1 smart contracts for a full security review.
Acceptance Criteria: Confirmation of the audit engagement and submission of the smart contracts for audit. Initial documentation prepared and submitted to the auditing firm.
Initial Audit Review and Feedback
Timeline: Month 2
Description: The audit firm conducts a thorough review of the Yamfore V1 smart contracts, identifying any vulnerabilities or performance optimizations. Initial feedback and findings are shared with the development team.
Acceptance Criteria: Receipt of the audit firm’s initial review report outlining any vulnerabilities and recommendations for improvements.
Implement Fixes and Conduct Final Testing (if needed)
Timeline: Month 3
Description: Based on the audit firm’s feedback, our development team will implement the necessary fixes and optimizations to address any identified vulnerabilities. Final tests will be conducted to ensure that the smart contracts are secure and fully functional.
Acceptance Criteria: Confirmation that all critical vulnerabilities have been addressed and the smart contracts pass final tests for security and functionality.
Publish Final Audit Report and Open Source Smart Contracts
Timeline: Month 3
Description: The final audit report will be released publicly, and the fully-audited Yamfore V1 smart contracts will be made open-source on a public GitHub repository.
Acceptance Criteria: Public release of the audit report, smart contracts, and supporting documentation on Yamfore’s GitHub.
Project Close-Out Report
Timeline: End of Month 4
Description: We will create and release a comprehensive project close-out report summarizing the audit process, results, and the overall impact on the Yamfore protocol and the wider Cardano community.
Acceptance Criteria: Completion and publication of the project close-out report, shared on Yamfore’s website and through Cardano community channels.
Brandon Chukwuka
Role: Lead Project Manager - Big Blymp Founder
Responsibilities: Overseeing the project, managing timelines, coordinating development, and ensuring milestones are met.
X: zartsnarf
Diego Macchi
Diego Macchi is a graduate from the Economic University of Buenos Aires. Cardano OG and member of de DeFi community.
Role: Community Advisor
Responsibilities: Community advisor and partnerships lead.
X: diegomac35
Dominic Wallis (Waalge)
Waalge is Math PhD. Formerly ML engineer and full-stack dev. DApp developer since Alonzo HF. Aiken contributor, particularly the nix maintenance and fuzz lib.
Role: Smart Contract Developer
Responsibilities: Developing the core Aiken smart contracts and ensuring the protocol’s security and functionality.
Developing the user interface for interacting with the lending pools, managing deposits, and yield visualization.
X: Waalge
GitHub: https://github.com/waalge
Jimmy
Role: Front End Developer
Responsibilities: Developing the front end smart contracts
X: 0xjimmy_eth
GitHub: https://github.com/0xjimmy
Gritar
Role: Graphic Designer
Responsibilities: design the user interface for interacting with the lending pools, managing deposits, and yield visualization.
X
Linda - MALU Pool
Role: Marketing and communications
Responsibilities: Video content creation and educational resources.
X: Cryptofly777
1- External Audit Firm:
Cost: 100,000 ADA
Description: Covers the cost of hiring a reputable third-party audit firm to conduct a comprehensive audit of Yamfore V1’s smart contracts.
2- Smart Contract Development and Bug Fixes:
Cost: 50,000 ADA
Description: Covers development work for implementing fixes and conducting final tests after the audit.
3- Project Management and Coordination:
Cost: 15,000 ADA
Description: Covers the costs of overseeing the project, coordinating with the audit firm, and ensuring timely delivery of milestones.
4-Documentation and Reporting:
Cost: 15,000 ADA
Description: Creation of comprehensive documentation.
Total Project Cost:
180,000 ADA
The cost of this project represents excellent value for the Cardano ecosystem by ensuring the security and transparency of Yamfore, a key DeFi protocol. A thorough security audit is essential to safeguard user funds and prevent potential vulnerabilities. The budget is proportional to the high standards expected in the blockchain industry, particularly for DeFi protocols managing significant funds.
The audit cost aligns with industry standards for complex DeFi projects. Security audits are critical to preventing exploits, and this investment ensures that Yamfore will meet the highest security standards.The developer rates are competitive for blockchain professionals and necessary to ensure that the smart contracts are secure and optimized.
By funding this project, the Cardano community is investing in a secure, open-source DeFi protocol, which will boost user confidence, liquidity, and developer engagement within the ecosystem.