CFL AuditReport InterFi
CFL AuditReport InterFi
CFL AuditReport InterFi
Summary
Platform Solidity
Mandatory Audit Check Static, Software, Auto Intelligent & Manual Analysis
Audit Summary
InterFi team has performed a line-by-line manual analysis and automated review of the smart
contract. The smart contract was analyzed mainly for common smart contract vulnerabilities,
v Crypto Fantasy League’s smart contract source code has LOW RISK SEVERITY.
For the detailed understanding of risk severity, source code vulnerability, and functional test, kindly
Table Of Contents
Project Information
Overview ................................................................................................................................................................................................ 4
Manual Analysis...............................................................................................................................................................................15
Report Summary
Legal Advisory
Project Overview
InterFi was consulted by Crypto Fantasy League to conduct the smart contract security audit of
CFL offers its users and holders of Token $CFL to earn and play same time. Instead of using
traditional technology CFL uses the blockchain and crypto as their payment options. With this CFL
is more secure and fast than any other Fantasy Sports Platform. Earn 3% reward just by holding
Language Solidity
Contract 0x78ebC325641c9dB284Fc0E69305aFbc0C92AB475
Website https://cryptofantasyleague.app/
Telegram https://twitter.com/CFLToken
Twitter https://twitter.com/CFLToken
Public logo
https://bscscan.com/address/0x78ebC325641c9dB284Fc0E69305aFbc0C92AB475#code
Symbol: CFL
https://github.com/interfinetwork/audited-codes/blob/main/CFL.sol
SHA-1 Hash
has scanned the contract and reviewed the project for common vulnerabilities, exploits, hacks, and
back-doors. Below is the list of commonly known smart contract vulnerabilities, exploits, and hacks:
Category
v Re-entrancy
v Unhandled Exceptions
v Integer Overflow
Smart Contract Vulnerabilities
v Unrestricted Action
v Typographical Errors
v Requirement Violation
v Ownership Takeover
v Deployment Consistency
Source Code Review v Repository Consistency
v Data Consistency
v Liquidity Access
The aim of InterFi’s “Echelon” standard is to analyze the smart contract and identify the
vulnerabilities and the hacks in the smart contract. Mentioned are the steps used by ECHELON-1 to
v Review of the specifications, sources, and instructions provided to InterFi to make sure we
v Manual review of code, which is the process of reading source code line-byline to identify
potential vulnerabilities.
v Test coverage analysis, which is the process of determining whether the test cases are
covering the code and how much code is exercised when we run those test cases.
v Symbolic execution, which is analysing a program to determine what inputs causes each
3. Best practices review, which is a review of the smart contracts to improve efficiency,
effectiveness, clarify, maintainability, security, and control based on the established industry
4. Specific, itemized, actionable recommendations to help you take steps to secure your smart
contracts
v Slither
v Consensys MythX
v Consensys Surya
This makes them very tempting attack targets, as a successful attack may allow the attacker to
directly steal funds from the contract. Below are the typical risk levels of a smart contract:
Vulnerable: A contract is vulnerable if it has been flagged by a static analysis tool as such. As we
will see later, this means that some contracts may be vulnerable because of a false-positive.
external attacker. For example, if the “vulnerability” flagged by a tool is in a function which requires
Exploited: A contract is exploited if it received a transaction on the main network which triggered
one of its vulnerabilities. Therefore, a contract can be vulnerable or even exploitable without having
been exploited.
Risk
Meaning
severity
This level vulnerabilities could be exploited easily, and can lead to asset loss, data
! Critical
loss, asset manipulation, or data manipulation. They should be fixed right away.
This level vulnerabilities are hard to exploit but very important to fix, they carry an
! High
elevated risk of smart contract manipulation, which can lead to critical risk severity
This level vulnerabilities are should be fixed, as they carry an inherent risk of future
! Medium
exploits, and hacks which may or may not impact the smart contract execution.
This level vulnerabilities can be ignored. They are code style violations, and
! Low informational statements in the code. They may not affect the smart contract
execution
💵 Function is payable
🔒 Function is locked
❗ Important functionality
Inheritance Graph
Review
v Be aware that active smart contract owner privileges constitute an elevated impact to
v Smart contract owner can blacklist certain wallets from interacting with the contract
function modules.
v The smart contract utilizes “SafeMath” function to avoid common smart contract
vulnerabilities.
library SafeMath {
function add(uint256 a, uint256 b) internal pure returns (uint256) {
uint256 c = a + b;
require(c >= a, "SafeMath: addition overflow");
uint256 c = a * b;
require(c / a == b, "SafeMath: multiplication overflow");
return c;
v The smart contract has 1 low severity issue which may or may not create any functional
vulnerability.
"owner": "_generated_diagnostic_collection_name_#0",
"source": "solc",
Compiler Check
100
95
90
85
Interface Safety Static Analysis
80
75
Compiler Check 90
Static Analysis 90
Software Analysis 95
Manual Analysis 92
Interface Safety 94
Auditor’s Verdict
InterFi team has performed a line-by-line manual analysis and automated review of the smart
contract. The smart contract was analyzed mainly for common smart contract vulnerabilities,
Crypto Fantasy League’s smart contract source code has LOW RISK SEVERITY.
v Be aware that active smart contract owner privileges constitute an elevated impact on smart
v Make sure that the project team’s KYC/identity is verified by an independent firm, e.g., InterFi.
v Always check if the contract’s liquidity is locked. A longer liquidity lock plays an important role
v Examine the unlocked token supply in the owner, developer, or team’s private wallets.
Understand the project’s tokenomics, and make sure the tokens outside of the LP Pair are
v Ensure that the project’s official website is hosted on a trusted platform, and is using an active
SSL certificate. The website’s domain should be registered for a longer period of time.
Important Disclaimer
InterFi Network provides contract auditing and project verification services for blockchain projects.
The purpose of the audit is to analyse the on-chain smart contract source code, and to provide
basic overview of the project. This report should not be transmitted, disclosed, referred to, or
relied upon by any person for any purposes without InterFi’s prior written consent.
InterFi provides the easy-to-understand assessment of the project, and the smart contract
(otherwise known as the source code). The audit makes no statements or warranties on the security
of the code. It also cannot be considered as an enough assessment regarding the utility and safety
of the code, bug-free status, or any other statements of the contract. While we have used all the
data at our disposal to provide the transparent analysis, it is important to note that you should not
rely on this report only — we recommend proceeding with several independent audits and a public
bug bounty program to ensure the security of smart contracts. Be aware that smart contracts
deployed on a blockchain aren’t resistant from external vulnerability, or a hack. Be aware that
active smart contract owner privileges constitute an elevated impact to smart contract’s safety
and security. Therefore, InterFi does not guarantee the explicit security of the audited smart
contract.
The analysis of the security is purely based on the smart contracts alone. No applications or
operations were reviewed for security. No product code has been reviewed.
This report should not be considered as an endorsement or disapproval of any project or team.
The information provided on this report does not constitute investment advice, financial advice,
trading advice, or any other sort of advice and you should not treat any of the report’s content as
such. Do conduct your own due diligence and consult your financial advisor before making any
investment decisions.
seamless and responsive. Some of our services: Blockchain Security, Token Launchpad, NFT
Marketplace, etc. InterFi’s mission is to interconnect multiple services like Blockchain Security,
DeFi, Gaming, and Marketplace under one ecosystem that is seamless, multi-chain compatible,
InterFi is built by a decentralized team of UI experts, contributors, engineers, and enthusiasts from
all over the world. Our team currently consists of 6+ core team members, and 10+ casual
contributors. InterFi provides manual, static, and automatic smart contract analysis, to ensure