FCS Proposal - Lelantus Spark Code Audit Proposal by HashCloak

A new proposal has been posted to the Firo Crowdfunding System.

  • Title: Lelantus Spark Code Audit Proposal by HashCloak
  • Author: mikerahq
  • Proposal type: Core
  • Link: click here

Use this topic to discuss this proposal!


Link to proposal is not working


Right now the price of Firo would make the proposal $113,681 instead of $80,000.
The Hashcloak is quoting USD values for milestones with a +10% Firo additional volatility buffer. So I’m assuming they ideally are looking for a USD equivalent of Firo.

Considering volatility can soar way more than 10%. Can we check if Hashcloak is willing to honor the audit even if Firo values drop to something like $1.XX which would be way beyond the 10% buffer.
If that’s not the case, then I think it’s better we just price the proposal in USD terms and sell the required Firo to reach the $80k audit bill.
I just want to avoid confusion later down the road regarding price or terms.


Spoke to HashCloak prior to this.
First of all, this is USD denominated. I asked Mikerah to add in a 10% anyway cause it’s better always to overshoot rather than undershoot. If the CFC funds are not utilized or are over, it will be returned to the CFC.

I offered to handle the liquidations for her through our normal method of using the bot to sell small portions over time to prevent price movement. The price is higher cause she based it off coingecko prior to the pump.


I figured that was the reason. What kind of timespan do you think CFC has to save up?


I personally don’t know where the price will go. Volatile period. I can of course just convert over time which can be fulfilled quite quickly tbh. Like 80k or so can easily be met in a day (usually much faster) but I can stretch it out a little. Just that more uncertainty the longer I stretch it out.


There’s an existing MAGIC fund on this so that will also reduce the amount the CFC/community needs to fund. It’s not much but it’s 8708 USD.

Thank you @rasikhmorani


How much do we have in CFC fund right now?


28K USD in liquidity here


Now CFC funds can be accurately tracked. 16K Firo atm


If we base it off today’s price (which just recently pumped hard so take this with a grain of salt) It’s 60k in FIRO and 28k in PCS liquidity. If we use the non PCS funds we can already fund the audit.

1 Like

Quick update:
@rasikhmorani from Arcadia has donated USD20,000 via Magic Grants (@sgp) and therefore the sum is reduced by the total amount already in Magic Grants which is USD28,708.

The Community Fund Committee (CFC) has approved to fund the balance from the community fund.

The following voted in favor of the proposal. @rasikhmorani @Fiendish @RyanApeFiro @rehrar @sproxet @nrsimha You can follow any discussions from this link here.


It’s hard for MAGIC Grants to accept FIRO sadly, but if we can take an asset on Kraken or FTX US with a good amount of liquidity, we can receive a donation for the remaining amount, convert to USD, and remove future volatility concerns for everyone.


All available CFC funds have been deployed towards the audit. We can probably begin the audit already. Note that the funds will be released in full first to allow conversion to stablecoin.


Status changed from ‘Funding Required’ to ‘WIP’

1 Like

Payment of 20504.0 FIRO sent

Sent to be steadily converted to USD to meet the amount.

All amounts are now in USD and are sitting with MAGIC Grants @sgp to handle the disbursements to Hashcloak @Mikerah on the agreed milestones for the audit.

MAGIC Grants Donations from Community: $27,926.61
Donations from Community to Crowdfunding and CFC: $52,073.39
TXID to Magic Grants: https://bscscan.com/tx/0x8da26b0e15c5ca93d0770d0e73e99c8d8b8cd8ac48fca8ec510e56c657e4478b

Thanks everyone who donated and special shoutout to Arcadia/Rasikh (@rasikhmorani) who generously contributed a huge chunk of it!

We plan to hand the Spark code for audit to Hashcloak no later than 15 October 2022.


After consulting with our core team to add devnet functionality for audit, we are handing over code on 22 October instead.

1 Like

We had our first kick-off meeting today with Hashcloak.

Audit scope is here: Lelantus Spark Code Audit Checklist - HackMD

Audit is set to begin on Monday 31st October 2022 and will run for about 6 weeks.

Once again huge thank you to everyone who donated and made this possible. We’ll keep everyone posted.

EDIT: fixed date


Audit is set to begin on Monday 31st October 2022?

Yes correct sorry :slight_smile:

When will Lelantus Spark go online after the audit is complete?

Huobi has changed again. Is there any chance for firo to re-list the Huobi exchange? Hong Kong is now attracting the cryptocurrency market

Update on the Lelantus Spark Code Audit

@rehrar @nrsimha @Fiendish @rasikhmorani @sproxet @OhGodAGirl @RyanApeFiro

The audit of Firo’s Lelantus Spark implementation has been concluded by HashCloak.

With an initial report delivered on 9 December 2022, the audit ran from 24 October 2022 until 28 November 2022. The final report taking note of all fixes done by the core team was delivered on 19 December 2022 and is available here.

Gladly to announce that no critical or high severity issues can be found thru the audit. The report’s other findings have all been resolved in the updated codebase. A copy of the report is available here.

We would like to express our utmost appreciation to HashCloak and Cypher Stack for their tremendous work on the audit and MAGIC Grants for assisting with the milestone payments to HashCloak.

Without the Firo community’s support, which fully funded the audit costing USD 80,000, this audit would not have been possible. We would like to give a special shout-out to Rasikh Morani from Arcadia Group and the Community Fund Committee for their generous contributions towards the audit.

Spark is the culmination of years of work of Firo from our roots with Zerocoin, Sigma and Lelantus. Our prior research removed trusted setup and the requirement of fixed denominations. The introduction of Spark heralds in fully confidential transactions, and powerful and flexible Spark addresses designed to protect recipient privacy. These addresses are also feature-packed with support for efficient multi-sig, incoming and outgoing view keys, diversified addressing and the ability to offload chain scanning and balance computation without giving up spend authority. Spark is also built to last, with a modular structure allowing components to be upgraded as the technology improves.

Lelantus Spark is live on devnet as we further clean up the code and fix bugs. We expect to launch testnet shortly in January.