
Sweat Economy: More than two years of security reviews
Published
Engagement Dashboard
36 of 37 findings fixed, including all critical and high-severity findings, according to the final reports.
Finding status at final report
Engagement record
- Client
- Sweat Economy
- Review period
- January 2024 to June 2026
- Public reviews
- 7
- Advisors
- Timur Güvenkaya, Michal Bajor
Findings by severity
“We worked with a few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than a one-off contract audit. They think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”
About Sweat Economy
Sweat Economy connects physical activity with crypto, allowing users to earn SWEAT tokens through their daily steps. Its NEAR smart contracts support token operations, reward claims, Jars, and Boosters.
20 million SWEAT token holders since launch, 3 million monthly active users, and over 20,000 new users joining daily (Sweat Economy website).
Between January 2024 and June 2026, Guvenkaya completed seven public security reviews covering new features, contract refactors, migrations, and the SWEAT token contract.
What we reviewed
Our work covered the Rust contracts behind several parts of the product: how rewards were recorded and claimed, how deposits and withdrawals were processed, who could call sensitive functions, and how account state moved between contract versions.
Each review had a defined scope. Together, they covered the following changes:
-
4 findingsAll fixed
-
3 findingsAll fixed
-
Sweat Booster & Step Jars
NFT operations, score recording, claims, withdrawals, and state consistency
- 2 Critical
- 3 High
- 2 Medium
7 findingsAll fixed
-
Jars Refactor
Refactored Jar logic, batch operations, race-condition checks, and fee calculations
- 1 High
- 2 Medium
- 1 Low
- 2 Info
6 findingsAll fixed
-
Sweat Jars Migration and Refactor
Account migration, double-claim risk, and signed-ticket reuse
- 1 Medium
- 1 Info
2 findingsAll fixed
-
Tiered Jars & Boosters
Tiered Jar and Booster changes, arithmetic overflow, and APY handling
- 1 Low
- 3 Info
4 findingsAll fixed
-
SWEAT NEP-141 Token
Token logic, deferred minting, storage accounting, migration, access control, and pause behavior
- 1 High
- 1 Medium
- 7 Low
- 2 Info
11 findings10 fixed, 1 acknowledged
Across these reviews, we reported 37 findings: 2 critical, 5 high, 6 medium, 15 low, and 9 informational.
Key findings
Unauthorized NFT transfers and reward claims
The Sweat Booster & Step Jars review identified two critical access-control issues.
The first affected nft_resolve_transfer. Without a restriction on who could call it, an attacker could steal NFTs from another account.
The second affected record_score. Missing caller validation allowed an attacker to assign an arbitrary score to their account and claim the corresponding reward.
The team fixed both issues by restricting the NFT resolver to contract self-calls and score recording to the manager.
Denial of service affecting user operations
The same Sweat Booster & Step Jars review identified high-severity issues that could block claims, withdrawals, and score recording. In one case, a callback failure could leave a user’s Jars locked, preventing further claims or withdrawals.
A separate finding in the Jars Refactor review showed how small deposits could disrupt batch operations. The production minimum deposit was 1 SWEAT, and an attacker could create numerous deposits for another user until operations exceeded the gas limit.
The report estimated that approximately 4,500 deposits, costing around $30 in SWEAT at the time, could cause withdraw_all, claim_total, and restake_all to fail.
The report records this issue as fixed through backend throttling, product-key requirements, monitoring of Jar creation, and restrictions on issuing tickets to suspicious users.
~$30estimated attack cost, paid in SWEAT, to make a user’s batch withdrawals and claims fail
Broken ownership records after NFT burns
The Sweat Booster & Step Jars review also found a high-severity state-handling issue. When a user who held more than one Booster NFT burned one of them, the contract deleted their entire entry in tokens_per_owner instead of removing only the burned token.
If that user minted again, the contract’s records disagreed with each other: the ownership list reported one token while the underlying set still held two.
The team fixed the issue by removing the owner’s entry only once it is empty.
Double claiming during account migration
The Sweat Jars Migration and Refactor review identified a medium-severity race condition.
State-changing functions in the old contract did not check whether the user’s account was migrating. Before the migration callback deleted that account, an attacker could claim rewards from the old contract and then claim them again from the new one.
The team fixed the issue by adding the account-migration check to state-changing functions.
Storage accounting in the SWEAT token contract
The SWEAT NEP-141 Token review identified a high-severity issue in the custom LookupMapAdapter that could undercharge storage for selected accounts.
The review also covered governance permissions, deferred minting, pause controls, fee calculations, and event emissions. Of its 11 findings, 10 were marked fixed. One informational finding concerning overlapping deferred batches after rollback was acknowledged.
Calculation and state-handling issues
Other findings addressed scores not being restored after failed transfers, fee rounding, arithmetic overflow, APY interpretation, and Booster lifecycle behavior.
These findings concerned specific contract behaviors that could produce incorrect records, unexpected calculations, or failed operations.