Dolomite
Security-review case study
“The Protocol Defence team’s attention to detail is excellent. Sometimes when you get a review done, you wonder how closely the team looked at your code and considered all surface area for attacks. We sleep better at night knowing that Protocol Defence went through every detail of our codebase rigorously.”
Dolomite
Overview
This page sets out the Protocol Defence security-review process and covers the engagement between the Protocol Defence team and Dolomite protocol.
Protocol Defence
Protocol Defence is a Smart Contract security service provider recasting the usual review model with two competing internal Protocol Defence teams, Smart Contract fuzzing, and a pay-per-vulnerability pricing option. Protocol Defence’s novel approach effectively incentivizes their security team to uncover as many vulnerabilities as possible and leave no stone unturned.
Dolomite
Dolomite is a next-generation decentralized money market protocol and DEX that offers broad token support and capital efficiency with its virtual liquidity system. Dolomite is capable of offering over-collateralized loans, margin trading, spot trading and other financial instruments.
Why teams pick Protocol Defence
Protocol Defence brings a security team with extensive experience in banking, DeFi, economics, trading, and software correctness. With a module as complex as Dolomite’s GM pools, it was essential that Dolomite engaged a highly specialized team offering rigorous attention to detail. Protocol Defence was exactly that team.
“Protocol Defence is amongst the most effective teams in the whole industry. They have a clear attention to detail that most auditors don’t have.”
Dolomite
The Report
Walking through the security reviews
In November of 2023 Protocol Defence ran a security review of Dolomite’s GMX V2 module. The auditing approach championed manual analysis to uncover novel exploits and heavy usage of Dolomite’s test suite to construct corner case tests and PoC’s.
A team of four security researchers, with two Lead Security Researchers, began a 2-week Protocol Defence review on the 1st of November. The review began with a kickoff call, where the Dolomite team detailed the GMX V2 integration and the Protocol Defence team stress tested the design with precise questions.
Throughout the review, findings and recommendations were sent with the Dolomite team as they were found by Protocol Defence. Explicit written PoC (proof-of-concept) tests accompanied High and Critical issues. Protocol Defence and Dolomite teams maintained continuous communication throughout the review to discuss the findings uncovered, potential remediations, and design improvements.
During the 2 week review a total of 2 Critical, 4 High, 13 Medium, and 15 Low findings were found by Protocol Defence, confirmed and fixed promptly by Dolomite, and these remediations were finally reviewed again by Protocol Defence.
“S-tier! Extremely professional and they know their practice really well.”
Dolomite
Results
During the review a total of 2 Critical, 4 High, 13 Medium, and 15 Low findings were reported and remediated. Protocol Defence takes the fix review process extremely seriously, uncovering a newly introduced Critical vulnerability from the remediations. After engaging with Protocol Defence, the Dolomite team is much more confident in the security of their codebase.
“Our team feels really good about the state of the system because of the degree of scrutiny it has gone under for the review”
Corey CaplanDolomite