Cointime

Download App
iOS & Android

Formally Verifying OpenZeppelin’s ERC-20 Implementation

Validated Project

Open Zeppelin’s ERC-20 reference implementation is widely used in Web3. A bug in it would be devastating for the many contracts that derive from it. But how do we know that it is correct? And how do we know contracts that derive from it do so correctly and do not introduce bugs?

In Part One of this series on formal verification, we explained how CertiK uses formal verification to mathematically prove the correctness of ERC-20 contracts that we audit. Let’s dive in and see what happens when we apply it to OpenZeppelin’s code.In Part One of this series on formal verification, we explained how CertiK uses formal verification to mathematically prove the correctness of ERC-20 contracts that we audit. Let’s dive in and see what happens when we apply it to OpenZeppelin’s code.

ERC-20 Standard Properties

At CertiK, we have written property templates that precisely describe the expected behaviors of ERC-20 token contracts. These templates are generic: our tools analyze the implementation details of each smart contract and adapt the templates accordingly. We have 38 property templates.

Let's look at some of the properties that we regularly verify on incoming ERC-20 token contracts. For the sake of readability, the formulas that follow are slightly simplified and omit some technical details that do not contribute to the overall understanding of the approach. CertiK's audit reports contain an appendix that reproduces the formulas that have been used during model checking. A list with all the formulas used in our ERC-20 verification approach is publicly available here.

The transferFrom() function in ERC-20 contracts requires special attention, as it needs to distinguish between the initiator of the transaction (the address is msg.sender), the accounts that spend and receive tokens, and because it needs to observe the limits imposed by the entries in _balances and _allowances.

Specifying Correct Allowance Updates

When transferFrom() succeeds, it must deduct the amount of tokens that have been transferred from the allowance that the sender has over the spender's account. However, many ERC-20 token contracts also allow the token owner to grant infinite allowance to another account. This is reflected by setting that account's allowance to the maximum value, i.e. to ((2^256)-1). Taking that exception into account, a correct allowance update can be specified by the following LTL formula 𝜑:

It states that when transferFrom() is invoked and terminates (without reverting) with a return value of true, we expect that the sender's allowance is either reduced by the amount of tokens in amt (the red subformula) or that the sender either is the owner of the transferred tokens or has unlimited allowance over the spender's tokens. In those cases, the allowance must remain unchanged (the blue subformula).

Specifying Dismissal of Transfers That Exceed the Allowance

Attempts to use transferFrom() to transfer an amount of tokens that exceeds one´s allowance should fail. This is formalized by 𝜓:

If the invocation of transferFrom() requests to transfer tokens from somebody other than their owner and if that transfer exceeds the sender's allowance, we expect the transaction to either revert, or to fail and signal its failure by returning false.

These are only two examples of the formalizations CertiK uses to capture the expected behaviors of ERC-20 token contracts. For more information about our properties and all technical details, refer to our property list.

OpenZeppelin's Reference Implementation for ERC-20 Contracts

The OpenZeppelin library provides reference implementations for many popular smart contracts. Its ERC-20 base contracts are popular and often used as building blocks for DeFi projects.

As many of the projects we audit contain contracts that derive from OpenZeppelin, we formally verified a set of 38 security properties on their ERC-20 reference implementation as of version 4.7.3. As can be seen the image below, all properties of the base contract are proven correct.

This result, however, tells us little about the security of actual ERC-20 token implementations, even when they derive from the OpenZeppelin contract! In actual blockchain projects, the reference implementation is modified by overriding its virtual functions and by introducing additional public APIs. What if someone makes a mistake?

The correctness of a base contract is generally not sufficient to ensure security in derived tokens! It is possible to introduce errors not only when overriding parts of the base implementation, but also by making changes to the contract’s state variables that were unforeseen in the base implementation.

OpenZeppelin implements their ERC-20 base contracts by making important state variables private. This ensures that contracts derived from them cannot simply destroy invariants that hold for those private variables. This encapsulation provides a certain level of protection from errors introduced within derived contracts.

Example: PancakeSwap's CAKE Token

PancakeSwap is one of the most popular decentralized exchanges. It is powered by the CAKE token, which implements the BEP20 standard (an extension of the ERC-20 standard). In general, CAKE tokens can be earned by staking and by providing liquidity to the exchange. Running our model checker on the CAKE token implementation successfully proves the basic ERC-20 behavior. The token implementation satisfies all of the properties that CertiK verifies on basic ERC-20 token contracts.

Conclusion

We’ve used formal verification to mathematically prove that OpenZeppelin’s reference ERC-20 implementation v4.8 meets basic ERC-20 properties. While it is not surprising that it does, this is good to know! We explained why just verifying OpenZeppelin’s implementation is not enough. You need to formally verify contracts that derive from it. Be sure to watch for our next blog post, where we discuss handling extensions to ERC-20 and other real-world challenges in verifying.

Read more: https://www.certik.com/resources/blog/7EELzmUpEOE7yhow8LpA3A-formally-verifying-openzeppelins-erc-20-implementation

Get the latest news here: Cointime channel — https://t.me/cointime_en

Comments

All Comments

Recommended for you

  • Putin States Negotiations with Ukraine Currently Impossible

    On October 10, Russian presidential aide Ushakov provided details about the phone call between the leaders of Russia and the United States. Ushakov stated that during the call, Putin elaborated on the measures Russia has taken in response to the terrorist attacks carried out by the Ukrainian armed forces. Putin indicated that Ukraine is attempting to undermine the Russian State Duma elections and is attacking civilians, which has compromised the possibility of immediately resuming negotiations. He also noted that Ukraine's attempts to hinder the advance of Russian troops have no prospects for success, as the Russian military currently holds complete initiative on the battlefield and is continuing to advance. Putin emphasized that due to Ukraine's stance, particularly its efforts to disrupt the Russian Duma elections, it is currently impossible to resume negotiations with Ukraine. Trump has instructed that the message conveyed by Putin during the call be communicated to the Ukrainian delegation. Ushakov mentioned that there has been no specific discussion yet regarding a potential bilateral meeting between Putin and Trump.

  • Telegram Renames Gram Wallet to Money and Launches for All Users

    On October 9, Telegram officially renamed its previously limited-access wallet service 'Gram wallet' to 'Money' and launched it to over one billion users across the platform. 'Money' is an integrated wallet for the Gram token, supporting storage, transfers, and purchases of platform gifts and collectible usernames. Additionally, the accompanying trading platform 'Walt' offers services for over 300 assets, including tokenized stocks, precious metals, perpetual contracts, and wealth management projects. Users can make instant transfers from 'Walt' to the 'Money' wallet without incurring network fees. The official statement also cautions that investing in crypto assets carries associated risks.

  • Blockchain.com Seeks Approval for Prediction Markets and Cryptocurrency Derivatives Trading

    On October 9, the crypto asset platform Blockchain.com submitted an application to the U.S. Commodity Futures Trading Commission (CFTC) seeking to obtain licenses for a designated contract market (DCM) and a futures commission merchant (FCM) to offer event contracts (prediction markets) and cryptocurrency derivatives trading services to U.S. users.

  • US May Seize Approximately $1 Billion in Cryptocurrency Related to Iran This Week

    U.S. Treasury Secretary Bencet stated at the NPolicy Summit held by Newsmax in Washington on Thursday that we may seize $1 billion in cryptocurrency this week, adding, "We know where it is, and we are isolating them." Bencet noted that the Trump administration's approach to Iran has shifted from 'maximum pressure' to 'absolute isolation,' with measures including maritime blockades, restrictions on air travel, and the cutting off of land routes. The UAE and Oman are cooperating with the U.S., which is also working with Pakistan and Turkey to cut off all land routes in and out of Iran.

  • Zcash Development Team Plans to Introduce Quantum-Resistant Signatures in January

    The development team of the privacy cryptocurrency Zcash (ZEC) plans to introduce post-quantum signature opcodes to the network in January next year, supporting hash-based signature technology to defend against potential quantum computing attacks. This solution primarily targets the transparent (public) payment pool, where approximately 70% of ZEC is currently stored. Although the developers have set January as the target deadline, the specific network activation time has not yet been finalized. This upgrade aims to prevent attackers from using existing public keys to reverse-engineer private keys and forge payment authorizations. Additionally, the Zcash node validator Zakura has launched a wallet tool based on Private Information Retrieval (PIR), allowing users to query balances across multiple addresses without revealing the correlation between those addresses to the server. Previously, Ethereum researcher Justin Drake warned that artificial intelligence could accelerate the cracking of traditional encryption algorithms and urged cryptocurrency holders to prepare for potential security threats.

  • BTC Surpasses $83,000

    Market data shows that BTC has surpassed $83,000, currently priced at $83,017.3, with a 24-hour increase of 0.66%. The market is highly volatile, so please ensure proper risk management.

  • Central Committee and State Council: Comprehensive Implementation of 'AI+' Initiative

    On October 9, the Central Committee of the Communist Party of China and the State Council issued the 'Opinions on Developing New Quality Productive Forces.' The opinions mention the comprehensive implementation of the 'AI+' initiative. This includes promoting the transformation of traditional industries through artificial intelligence, accelerating the development of new-generation intelligent terminal applications such as smart connected new energy vehicles, AI smartphones and computers, and humanoid robots. It aims to speed up innovation in digital intelligence technologies like artificial intelligence, break through foundational theories and core technologies, and strengthen the efficient supply of computing power, algorithms, and data. The strategy involves tailored approaches based on local conditions and industry-specific policies to layout national pilot bases for AI industry applications and high-value application scenarios, vigorously promoting the application of AI across various sectors. Additionally, it emphasizes the establishment of a technology monitoring, risk warning, and emergency response system to ensure that artificial intelligence is safe, reliable, and controllable.

  • U.S. Government-Related Wallet Deposits 17,733 BTC and 750 WBTC to Coinbase Prime

    On October 9, according to monitoring by Lookonchain, wallets associated with the U.S. government have deposited 17,733 BTC (worth $1.48 billion) and 750 WBTC (worth $62 million) into Coinbase Prime over the past three days. According to tagging data from Arkham, these wallets currently hold cryptocurrency assets valued at $25.4 billion, with Bitcoin alone valued at $25.3 billion.

  • ETH Falls Below $2500

    Market data shows that ETH has fallen below $2500, currently priced at $2499.87, with a 24-hour decline of 2.55%. The market is experiencing significant volatility, so please ensure proper risk management.

  • ETH Surpasses $2500

    Market data shows that ETH has surpassed $2500, currently priced at $2500.13, with a 24-hour decline of 2.21%. The market is experiencing significant volatility, so please ensure proper risk management.