$1,000,000 in security audit grants are live now, Apply here →

← Case Studies

Umami

Security review case study

“Our experience with Keel Formal has been amazing, the level of detail they went to in reviewing the code as well as understanding the conceptual ideas enabled them to highlight important security considerations throughout the codebase. All security researchers on the team were exceptional at understanding all intricacies of the design and the team is well suited to audit any novel DeFi product that comes their way.”

Umami ChanUmami DAO

Overview

This document serves as an exposition of the Keel Formal security review process, detailing an engagement between the Keel Formal team and Umami Finance.

Get a quote

Keel Formal

Keel Formal is a Smart Contract security service provider re-imagining the traditional audit model with two competing internal Keel Formal teams, Smart Contract fuzzing, and a Pay-Per-Vulnerability pricing alternative. Keel Formal’s novel approach effectively incentivizes their security team to uncover as many vulnerabilities as possible and leave no stone unturned.

Umami Finance

Umami is a is a hybrid Decentralized Finance (DeFi) protocol pioneering the institutional adoption of DeFi. Umami offers yield vaults which employ a capital efficient hedging strategy that mitigates depositors’ exposure to unwanted market delta in GMX V2 markets while continuing to pass on nearly all of its highly-competitive APR.

Why Keel Formal?

Keel Formal boasts a security team with extensive experience in banking, DeFi, economics, trading, and software correctness. As Umami was launching the Smart Contract infrastructure for their delta-neutral GM vaults, it was paramount to engage a team with rigorous experience with GMX. Having spent over a year performing security analysis on the GMX V2 perpetuals system, Keel Formal was a clear choice.

"The Keel Formal team was responsive and thorough in their approach to reviewing and testing the code. Any questions we had were answered promptly and they gave advice on different aspects of the code even before the audit began."

Umami ChanUmami DAO

The Report

View the report

Dissecting The Security Review

In the 3 week period from December 11th to December 29th, Umami engaged Keel Formal to perform a security review of their GM vaults using their unique internal hedging mechanisms. During the engagement 6 security researchers uncovered multiple Critical & High severity findings in the project.

The Kickoff Call

The engagement officially began on December 11th with a kickoff call between Keel Formal and Umami the day prior. During the kickoff call, members from Umami team shared an overview of their vaults and answered probing questions from Keel Formal security researchers.

"Any questions we had were answered promptly and they gave advice on different aspects of the code even before the audit began."

Umami ChanUmami DAO

The Research

Following the kickoff call, the Keel Formal team focused first on gaining a deep understanding of the codebase, constructing diagrams and carrying out internal discussions on the behavior of the system.

Following these discussions, Keel Formal identified several key points in the Umami system which were vulnerable to exploitation. These findings were immediately shared with the Umami team using a shared Notion database for the engagement.

The Testing

After gaining a strong understanding of the logic of Umami’s Smart Contract system and having battle tested it against manual efforts, Keel Formal elected to conduct further assurance on the system with both stateful and stateless fuzzing efforts.

Keel Formal’s fuzzing efforts proved to be fruitful as they uncovered findings such as "AV-1" & "LCY-1" which were promptly shared with the Umami team.

The Remediation

While Keel Formal continued to conduct the security review, Umami engineers were able to implement the recommendations made — as these findings and recommendations were shared throughout the engagement.

After completing the two week period focusing on the frozen commit, Keel Formal conducted a comprehensive review of the remediations made by Umami. Systematically, Keel Formal verified that the remediations made resolved the issues uncovered and did not introduce any new issues.

”Keel Formal discovered notable vulnerabilities which would of greatly impacted the protocol security if not uncovered. They did a good job at uncovering these early.”

Umami ChanUmami DAO

Results

Throughout the 3 week engagement, Keel Formal uncovered 3 Critical, 6 High, 8 Medium, and 41 Low findings which were remediated by the Umami team and promptly reviewed by Keel Formal.

Keel Formal’s attention to detail and immense verification efforts were key in preparing the codebase for a successful launch.

“I would recommend Keel Formal to others looking for a comprehensive audit specifically for complex projects.”

Umami ChanUmami DAO

Get a quote