← Case Studies

Umami

Security-review case study

“Our experience with Protocol Defence has been amazing, the level of detail they went to in reviewing the code as well as understanding the conceptual ideas enabled them to highlight important security considerations throughout the codebase. All security researchers on the team were exceptional at understanding all intricacies of the design and the team is well suited to audit any novel DeFi product that comes their way.”

Umami ChanUmami DAO

Overview

This page sets out the Protocol Defence security-review process and covers a review between the Protocol Defence team and Umami Finance.

Ask for a quote

Protocol Defence

Protocol Defence is a Smart Contract security service provider recasting the usual review model with two competing internal Protocol Defence teams, Smart Contract fuzzing, and a pay-per-vulnerability pricing option. Protocol Defence’s novel approach effectively incentivizes their security team to uncover as many vulnerabilities as possible and leave no stone unturned.

Umami Finance

Umami is a is a hybrid Decentralized Finance (DeFi) protocol pioneering the institutional adoption of DeFi. Umami offers yield vaults which employ a capital efficient hedging strategy that mitigates depositors’ exposure to unwanted market delta in GMX V2 markets while continuing to pass on nearly all of its highly-competitive APR.

Why teams pick Protocol Defence

Protocol Defence brings a security team with extensive experience in banking, DeFi, economics, trading, and software correctness. As Umami was launching the Smart Contract infrastructure for their delta-neutral GM vaults, it was essential to engage a team with rigorous experience with GMX. Having spent over a year performing security analysis on the GMX V2 perpetuals system, Protocol Defence was a clear choice.

"The Protocol Defence team was responsive and thorough in their approach to reviewing and testing the code. Any questions we had were answered promptly and they gave advice on different aspects of the code even before the review began."

Umami ChanUmami DAO

The Report

Open the report

Walking through the security review

In the 3 week period from December 11th to December 29th, Umami engaged Protocol Defence to perform a security review of their GM vaults using their unique internal hedging mechanisms. During the review 6 security researchers found multiple Critical & High severity findings in the project.

The kickoff

The engagement officially began on December 11th with a kickoff call between Protocol Defence and Umami the day prior. During the kickoff call, members from Umami team shared an overview of their vaults and answered probing questions from Protocol Defence security researchers.

"Any questions we had were answered promptly and they gave advice on different aspects of the code even before the review began."

Umami ChanUmami DAO

The research

Following the kickoff call, the Protocol Defence team focused first on gaining a deep understanding of the codebase, constructing diagrams and carrying out internal discussions on the behavior of the system.

Following these discussions, Protocol Defence identified several key points in the Umami system which were vulnerable to exploitation. These findings were immediately shared with the Umami team using a shared Notion database for the engagement.

The Testing

After gaining a strong understanding of the logic of Umami’s Smart Contract system and having pressure-tested it against manual efforts, Protocol Defence elected to conduct further assurance on the system with both stateful and stateless fuzzing efforts.

Protocol Defence’s fuzzing efforts proved to be fruitful as they found findings such as "AV-1" & "LCY-1" which were promptly shared with the Umami team.

The fix pass

While Protocol Defence continued to conduct the security review, Umami engineers were able to implement the recommendations made — as these findings and recommendations were sent across the review.

After completing the two week period focusing on the frozen commit, Protocol Defence conducted a comprehensive review of the remediations made by Umami. Systematically, Protocol Defence verified that the remediations made resolved the issues found and did not introduce any new issues.

”Protocol Defence discovered notable vulnerabilities which would of greatly impacted the protocol security if not uncovered. They did a good job at uncovering these early.”

Umami ChanUmami DAO

Results

Throughout the 3 week engagement, Protocol Defence found 3 Critical, 6 High, 8 Medium, and 41 Low findings which were remediated by the Umami team and promptly reviewed by Protocol Defence.

Protocol Defence’s attention to detail and immense verification efforts were key in preparing the codebase for a successful launch.

“I would recommend Protocol Defence to others looking for a comprehensive audit specifically for complex projects.”

Umami ChanUmami DAO

Ask for a quote