LUKSO · Universal Profiles · LSP Standards

LUKSO Smart Contract Audit

Quick Answer

  • LUKSO is EVM-compatible — standard Solidity analysis applies — but Universal Profiles are smart-contract accounts (LSP0/ERC725Account) controlled through the LSP6 Key Manager, not plain wallets, which is a fundamentally different permission model to audit.
  • A public Code4rena audit of LUKSO found that Key Manager permissions can survive an ownership transfer, letting a former owner retain control — permission misconfiguration is the highest-risk LUKSO-specific pattern.
  • SmartContractAuditor.ai covers both standard Solidity vulnerabilities and LSP-specific patterns: Key Manager permission scope, Universal Receiver Delegate risk, and LSP7/LSP8 operator authorization.

LUKSO's EVM compatibility means Solidity developers can deploy without rewriting code — but the Universal Profile standard (LSPs) introduces an account model built for permissioned, programmable identity, not just asset custody. That flexibility is the point, and it's also where misconfiguration turns into a real security gap.

LUKSO / Universal Profile Security Considerations

Smart-Contract-Based Accounts

A Universal Profile (LSP0/ERC725Account) is a smart contract, not an EOA. It holds assets and identity data directly, and every interaction with it goes through the account's own contract logic rather than a raw private key signature.

LSP6 Key Manager Permissions

Control over a Universal Profile is delegated to one or more controller addresses via the Key Manager, each with scoped permissions. Overly broad grants — especially the SUPER_ permissions that bypass restriction checks — are the most common LUKSO-specific misconfiguration.

Universal Receiver (LSP1)

Every incoming asset transfer can trigger a Universal Receiver Delegate contract automatically. This enables real functionality (auto-cataloging, custom accept/reject logic) but means delegate contracts need the same reentrancy discipline as any other externally-triggered code path.

Full EVM Compatibility

All standard Ethereum Solidity vulnerability classes still apply on LUKSO: reentrancy, oracle manipulation, access control flaws, flash loan attacks. LSP-specific risks are additive, not a replacement for standard EVM security review.

Audit Your LUKSO Contract Now

Free scan · results in 60 seconds · EVM + LSP-specific vulnerability detection

LUKSO / Universal Profile Vulnerability Classes

Vulnerability TypeSeverityDescriptionExample
Stale Key Manager Permissions After Ownership Transfer
Critical
A Universal Profile's LSP6 Key Manager grants permissions to specific controller addresses. When ownership of the profile is transferred to a new owner, permissions granted to the previous controller are not automatically revoked. A Code4rena audit of LUKSO in 2023 found this exact issue: a former owner can retain dangerous permissions after the profile changes hands.A Universal Profile is sold or transferred to a new owner, but the previous owner's controller address still holds SETDATA or CALL permissions on the Key Manager — letting them modify profile data or execute transactions on an account they no longer own.
Overly Broad SUPER_ Permissions
Critical
LSP6 defines 'SUPER_' permissions (SUPER_CALL, SUPER_TRANSFERVALUE, SUPER_SETDATA) that bypass the AllowedCalls and AllowedERC725YDataKeys restrictions entirely. Granting one of these to a third-party controller — a dApp, an automation bot, a Grid mini-app — gives that address effectively unrestricted control over the entire account, not just a scoped subset of actions.A project grants SUPER_CALL to a bot that's supposed to only call one specific contract function — the bot (or anyone who compromises it) can now call any contract from the profile, not just the intended one.
Unvalidated Universal Receiver Delegate Logic
High
LSP1's universalReceiver() function fires automatically whenever a Universal Profile receives any asset — LYX, an LSP7 token, or an LSP8 NFT. If a Universal Receiver Delegate contract is set to handle these notifications, its logic executes on every incoming transfer. An unguarded delegate is a reentrancy-equivalent risk, the same class of problem ERC-777's tokensReceived hook caused in early DeFi.A Universal Receiver Delegate that updates internal accounting state without a reentrancy guard — an attacker sends a token that itself calls back into the profile mid-transfer, exploiting the inconsistent state before the first transfer completes.
Unscoped LSP7/LSP8 Operator Authorization
High
authorizeOperator is LSP7/LSP8's equivalent of ERC-20's approve or ERC-721's setApprovalForAll. LSP8 adds per-tokenId operator scoping, but it's often misused as if it granted global authority, or never revoked after the interaction it was meant for is done — the same unlimited-approval risk that's caused real losses across standard ERC token ecosystems.A marketplace contract is authorized as an operator for a full LSP8 collection to enable listing, and is never revoked after the sale completes — a bug or compromise in that marketplace contract can move any token in the collection indefinitely.
Custom LSP7/LSP8 Extensions Skipping Parent Hooks
Medium
Like OpenZeppelin's ERC-20 and ERC-721, LSP7 and LSP8 are meant to be extended. Teams that add custom mint, burn, or transfer logic without calling the parent contract's hooks — or without correctly validating the force and data parameters — can break the Universal Receiver notification guarantee or bypass standard behavior receivers rely on.A custom LSP7 extension overrides _transfer to add a fee, but forgets to call the parent's notification logic — recipient contracts that depend on receiving a universalReceiver callback never get notified, silently breaking any integration that relies on it.

Vulnerability #1 is grounded in a real, public finding: Code4rena's June 2023 LUKSO audit.

LUKSO Smart Contract Audit — Frequently Asked Questions

Is LUKSO EVM-compatible, and can I use the same audit tools as Ethereum?
Yes — LUKSO is a Layer 1 EVM-compatible blockchain, and Solidity contracts deploy and behave the same way they do on Ethereum. All standard EVM-level security analysis applies. But LUKSO's core primitive, the Universal Profile, is a smart-contract-based account (LSP0/ERC725Account) controlled through the LSP6 Key Manager — a fundamentally different permission model than a plain externally-owned wallet, with its own risk patterns that Ethereum-focused tools weren't built to catch.
What is a Universal Profile, and how is it different from a regular wallet?
A regular wallet (an EOA) is controlled by a single private key. A Universal Profile is a smart contract itself (following the LSP0/ERC725Account standard), and control over it is delegated through the LSP6 Key Manager to one or more 'controller' addresses, each with its own scoped permissions. This enables features a wallet can't do natively — granular permissions, social recovery, gasless meta-transactions — but it also means the security question isn't just 'who has the private key,' it's 'what permissions does every controller actually have, and are any of them broader than intended.'
What's the single biggest LUKSO-specific security risk?
Key Manager permission misconfiguration. A public Code4rena audit of LUKSO in 2023 found that permissions granted to a previous controller can survive an ownership transfer, letting a former owner retain control they shouldn't have. More broadly, LSP6's 'SUPER_' permissions bypass the restriction system entirely — granting one to a controller that only needs limited access is the LUKSO equivalent of handing out admin rights when a scoped role would do.
What is the Universal Receiver, and why does it matter for security?
LSP1's universalReceiver() function fires automatically whenever a Universal Profile receives any asset — LYX, an LSP7 token, or an LSP8 NFT — and if a delegate contract is configured to handle it, that delegate's code runs as part of the transfer. It's a powerful feature (automatic asset cataloging, custom accept/reject logic), but any delegate contract that isn't carefully guarded against reentrancy or unexpected callers becomes an attack surface that fires on every incoming transfer, not just ones the profile owner initiated.
How much does a LUKSO / Universal Profile smart contract audit cost?
LUKSO contracts are EVM-compatible Solidity, so standard audit-firm rates apply — typically $15,000–$150,000 depending on scope and complexity, though LSP-specific expertise (Key Manager permission review, Universal Receiver Delegate logic) is still a narrower specialty than general Solidity auditing. AI-powered analysis at SmartContractAuditor.ai covers both standard Solidity vulnerability classes and LUKSO/LSP-specific patterns, with results in under 60 seconds — free for the first scan.
Written by Duron Epps, Founder of SmartContractAuditor.ai · Last updated September 2026