Risk on Beefy project

Overview

Beefy.Finance is a yield farming optimizer on Binance Smart Chain which automates investment strategies utilizing liquidity pools. The platform helps investors to interact‌ ‌with‌ various yield‌ farming opportunities, ‌without‌ ‌having‌ ‌to‌ ‌constantly review and manually execute their investment strategy.

Investor

N/A

Partner

N/A

Stats

Total value locked: $ 54.39M

Market Cap: $ 147,269,621

                                                              UTC 2021.3.25 02:47

Token

NAME: BIFI

Type: BEP-20

BIFI Token Distribution:

Total Supply: 80,000

Circulating Supply: 76,000

Usage:

Mining Rewards

Governance: By holding BIFI, either staked in the governance pool or BIFI Maxi Vault, users have the right to create proposals and votes. Users do not need to un-stake their tokens to participate in the voting process.

Staking: A portion of the fees paid by Beefy.Finance yield farming vault users is distributed to BIFI token holders staked in the governance pool and the BIFI Maxi Vault. Rewards are paid out in wBNB and BIFI respectively.

Official Links

Website: https://beefy.finance/

Github: BeefyFinance · GitHub

Contracts on BSC: 0xCa3F508B8e4Dd382eE878A314789373D80A5190A

Audit Report: Certik:

Risk Framework

Dangerous usage of tx.origin tx.origin

In an extreme case, if the contract owner calls some malicious contract A, and within A the calling stack is like: A → … → masterchef → … → vault → StrategyCake.withdraw , there is a chance that some unexpected behavior would happen. Such potential issue should be within a controllable range, considering the working flow after the owner checking, and also we assume vault is under control of project Beefy. But we still want to point out project client should be careful about using tx.origin .