Contest ran 3 May 20229 May 2022

6 day contest

Cudos contest

Decentralised cloud computing for Web3.

$75,000 USDC

Total Awards

Cudos contest details

Contest Scope

This contest is open for one week. Representatives from Cudos will be available in the Code Arena Discord to answer any questions during the contest period. The focus for the contest is to try and find any logic errors or ways to drain funds in a way that is advantageous for an attacker at the expense of users with funds invested in the protocol. Wardens should assume that governance variables are set sensibly (unless they can find a way to change the value of a governance variable, and not counting social engineering approaches for this).


The Cudos Network is a special-purpose blockchain designed to provide high-performance, trustless, and permissionless cloud computing for all. It is based on Cosmos SDK. The focus of the contest is the Bridge which contains a Cosmos module, Solidity smart contracts and associated relaying/oracle code.

It currently supports bridging of CUDOS tokens between the Ethereum and Cudos ecosystems. It is based on Althea's Gravity Bridge.

Design Notes

  • CUDOS Network supports sending the native Cudos token to an EMV based network.
  • CUDOS Network Gravity Bridge is bidirectional.
  • CUDOS Network Gravity Bridge accepts transactions verified only by preaproved set of validators.
  • Batches are automaticaly sent every X blocks.
  • Minimum amount and minimum fee are required for a transfer. Those values can be changed only by admin defined in CudosAccessControls.
  • Every user can bridge tokens.

Example flows

Token transfer

Usage example:

Ethereum to Cudos Network

  1. User sends 50 CUDOS to the Gravity.sol specifying the receiver address via the SendToCosmos. The address is a Cudos network address.
  2. Validators on the Cudos chain see that this has happened and mint 50 CUDOS for the address you specified on the Cudos chain.

Cudos Network to Ethereum

  1. User wants to send 50 CUDOS with the gravity module to an Ethereum address. Calling the send-to-eth method they specify an Ethereum address and amount.
  2. Validators on the Cudos chain lock the Cudos token in the gravity module and unlock 50 CUDOS on the Ethereum Network.

Gravity module

The Gravity module is resposible for handling all transactions in the Cudos Network related to the bridge.

Smart Contracts

The following contracts are in-scope for the audit.


Gravity.sol (~600 sloc)

Stores a real time representation of the validator set of the Cudos Network. For optimisation hash is representing the full validator set and voting power. This contract's events are tracked by the oracle component of the bridge in order to perform actions triggered on the Ethereum network on the Cudos Network.

CosmosToken.sol (~15 sloc)

Out of scope contracts


ERC-20 Cudos token contract.

CudosAccessControl.sol (~70 sloc)

Access controls contract managing user roles. Gravity.sol verifies ceraiain functions access based on the user defined roles.


For local builds you can use the Cudos Builders


Token repo:

Cudos-noded repo:

Gravity bridge repo:

Bridge user doc:

Network resources:

Test deployments

Gravity contracts: 0x8f8baFF99FCe5F6Df2abc073A55aB69D8aF13D22

Block Explorer:

Bridge UI: