• © Goverland Inc. 2026
  • v1.0.8
  • Privacy Policy
  • Terms of Use
ExactlyExactlyby0x378730E6460D5f811a5cd46A198A12D79093C6360x3787…C636

[EXAIP-10] Installments Router and New Market Roles, First Audits

Voting ended almost 2 years agoSucceeded

Proposal ID: EXAIP-10 Proposer: Exactly Core Team and Hashlock Date: March 20, 2024

Summary

Based on the IRM v2 audit conducted by Hashlock (https://github.com/exactly/audits/blob/main/Hashlock%20Interest%20Rate%20Model%20v2%20(Mar-24).pdf), Exactly's team have reached out to us again to ask for a new quote for the new InstallmentRouter smart contract, as well as an audit for the upgrades made to the New Markets Roles and States contract.

The IRM v2 audit proposal can be found here (https://gov.exact.ly/#/proposal/0xe713fffedc13a7dd14ef233c42a7e09cb4e376c3fbbe4c3c94227717b332182e)

The code in scope, shared by Exactly

  1. Installments Router: a new contrat that will allow to pay a loan in multiplice intallments with one transaction using the new Interest Rate Model.
  • original code: new contract
  • final code: https://github.com/exactly/protocol/commit/566b5579c7618db91ccc1023a518f4640850239c
  1. New Market Roles and States that will allow to implement an automatic pausing role related to the [EXAIP-07] EXA Security Grant Proposal by Hypernative.
  • original code: https://github.com/exactly/protocol/commit/d424a0758a877e95a9f21a3685c680e086dc2321
  • wip branch: https://github.com/exactly/protocol/tree/new-states
  • diff: https://github.com/exactly/protocol/compare/02fda2b81713c60665751eaf553acb28fdcd3797...new-states

Proposal

Same methodology as previously:

Hashlock is to prepare works for the following: a) A comprehensive report detailing the contracts security and efficiency, found via methods including; • Manual line-by-line code review • Manual penetration testing • Simulated Protocol interactions • Software tool analysis • SWC-Registry vulnerability Testing • Specification to function matching • Optimisation and code convention checks • Code analysis, static security analysis, penetration and exploitation, vulnerability identification, and recommendations on resolving issues. b) Pre Audit Research and context finding. c) Communication with the smart contract developer around our findings and recommendations. d) Preliminary Report, Communication with you around our findings and recommendations. e) Creation and provision of marketing graphics to use as social and website certification.

Hashlock takes into consideration all preliminary documentation, content, profit & overheads associated with this project.

Compensation and timeline

Due to this newly born ongoing partnership between Hashlock and Exactly, Hashlock will charge an audit fee of USD 5,000 paid in $EXA tokens again - at market price during 14 days - to conduct the audit, create and deliver the report and communicate our findings. Hashlock envisages a timeline of 14 days to finalise the preliminary report, with a start date on the 28th of March, following the approval of this proposal.

The EXA tokens will be received during the 14 days period, whereafter the preliminary report is shared.

Off-Chain Vote

Approve
358.73K EXA100%
Deny
0 EXA0%
Quorum:359%
Download mobile app to vote

Timeline

Mar 20, 2024Proposal created
Mar 21, 2024Proposal vote started
Mar 26, 2024Proposal vote ended
Mar 26, 2024Proposal updated