Canonical page: <https://www.guvenkaya.co/case-studies/sweat-economy>

![Two oversized sneaker soles mid-stride, rendered in Sweat pink ASCII characters on deep violet](https://www.guvenkaya.co/v2/blog/covers/sweat-economy-case-study-soles.png)

[Case study](https://www.guvenkaya.co/blog?type=case-studies)

# Sweat Economy: More than two years of security reviews

Published Oct 7, 2026

## Engagement Dashboard

**36 of 37 findings fixed**, including all critical and high-severity findings, according to the final reports.

### Finding status at final report

**37** Raised

**36** Fixed

**1** Acknowledged

### Engagement record

- Client

  Sweat Economy

- Review period

  January 2024 to June 2026

- Public reviews

  7

- Advisors

  Timur Güvenkaya, Michal Bajor

### Findings by severity

- Critical **2**
- High **5**
- Medium **6**
- Low **15**
- Informational **9**

> “We worked with a few known security ‘brands’ in the past. Timur Güvenkaya and his team are different. They understand that security is a continuous process rather than a one-off contract audit. They think about a wider perimeter and work in an extremely agile fashion. Most of our work now goes to them.”

**Oleg Fomenko** Co-Founder and CEO at Sweat Economy

## About Sweat Economy

Sweat Economy connects physical activity with crypto, allowing users to earn SWEAT tokens through their daily steps. Its NEAR smart contracts support token operations, reward claims, Jars, and Boosters.

**20 million SWEAT token holders since launch, 3 million monthly active users, and over 20,000 new users joining daily** ([Sweat Economy website](https://swe.at/)).

Between January 2024 and June 2026, Guvenkaya completed seven public security reviews covering new features, contract refactors, migrations, and the SWEAT token contract.

## What we reviewed

Our work covered the Rust contracts behind several parts of the product: how rewards were recorded and claimed, how deposits and withdrawals were processed, who could call sensitive functions, and how account state moved between contract versions.

Each review had a defined scope. Together, they covered the following changes:

1. January 2024

   ### [Defer](https://www.guvenkaya.co/reports/sweat-defer)

   Deferred claiming, batch processing, callbacks, and fee rounding

   - 3 Low
   - 1 Info

   **4 findings** All fixed

2. April 2024

   ### [Burn Model](https://www.guvenkaya.co/reports/sweat-burn-model)

   Burn calculations, account handling, and gas checks before cross-contract calls

   - 3 Low

   **3 findings** All fixed

3. August 2024

   ### [Sweat Booster & Step Jars](https://www.guvenkaya.co/reports/sweat-booster)

   NFT operations, score recording, claims, withdrawals, and state consistency

   - 2 Critical
   - 3 High
   - 2 Medium

   **7 findings** All fixed

4. December 2024

   ### [Jars Refactor](https://www.guvenkaya.co/reports/sweat-jars-refactor)

   Refactored Jar logic, batch operations, race-condition checks, and fee calculations

   - 1 High
   - 2 Medium
   - 1 Low
   - 2 Info

   **6 findings** All fixed

5. May 2025

   ### [Sweat Jars Migration and Refactor](https://www.guvenkaya.co/reports/sweat-jars-migration)

   Account migration, double-claim risk, and signed-ticket reuse

   - 1 Medium
   - 1 Info

   **2 findings** All fixed

6. January 2026

   ### [Tiered Jars & Boosters](https://www.guvenkaya.co/reports/sweat-tiered-jars)

   Tiered Jar and Booster changes, arithmetic overflow, and APY handling

   - 1 Low
   - 3 Info

   **4 findings** All fixed

7. June 2026

   ### [SWEAT NEP-141 Token](https://www.guvenkaya.co/reports/sweat-token)

   Token logic, deferred minting, storage accounting, migration, access control, and pause behavior

   - 1 High
   - 1 Medium
   - 7 Low
   - 2 Info

   **11 findings** 10 fixed, 1 acknowledged

Across these reviews, we reported **37 findings: 2 critical, 5 high, 6 medium, 15 low, and 9 informational**.

## Key findings

2 Critical Fixed

### Unauthorized NFT transfers and reward claims

The [**Sweat Booster & Step Jars**](https://www.guvenkaya.co/reports/sweat-booster) review identified two critical access-control issues.

The first affected `nft_resolve_transfer`. Without a restriction on who could call it, an attacker could steal NFTs from another account.

The second affected `record_score`. Missing caller validation allowed an attacker to assign an arbitrary score to their account and claim the corresponding reward.

The team fixed both issues by restricting the NFT resolver to contract self-calls and score recording to the manager.

- [GUV-1, GUV-2 Sweat Booster & Step Jars Security Review](https://www.guvenkaya.co/reports/sweat-booster#guv-1)

3 High Fixed

### Denial of service affecting user operations

The same [**Sweat Booster & Step Jars**](https://www.guvenkaya.co/reports/sweat-booster) review identified high-severity issues that could block claims, withdrawals, and score recording. In one case, a callback failure could leave a user’s Jars locked, preventing further claims or withdrawals.

A separate finding in the [**Jars Refactor**](https://www.guvenkaya.co/reports/sweat-jars-refactor) review showed how small deposits could disrupt batch operations. The production minimum deposit was 1 SWEAT, and an attacker could create numerous deposits for another user until operations exceeded the gas limit.

The report estimated that approximately **4,500 deposits, costing around $30 in SWEAT at the time**, could cause `withdraw_all`, `claim_total`, and `restake_all` to fail.

The report records this issue as fixed through backend throttling, product-key requirements, monitoring of Jar creation, and restrictions on issuing tickets to suspicious users.

**\~$30** estimated attack cost, paid in SWEAT, to make a user’s batch withdrawals and claims fail

- [GUV-3, GUV-4 Sweat Booster & Step Jars Security Review](https://www.guvenkaya.co/reports/sweat-booster#guv-3)
- [GUV-1 Jars Refactor Security Review](https://www.guvenkaya.co/reports/sweat-jars-refactor#guv-1)

High Fixed

### Broken ownership records after NFT burns

The [**Sweat Booster & Step Jars**](https://www.guvenkaya.co/reports/sweat-booster) review also found a high-severity state-handling issue. When a user who held more than one Booster NFT burned one of them, the contract deleted their entire entry in `tokens_per_owner` instead of removing only the burned token.

If that user minted again, the contract’s records disagreed with each other: the ownership list reported one token while the underlying set still held two.

The team fixed the issue by removing the owner’s entry only once it is empty.

- [GUV-5 Sweat Booster & Step Jars Security Review](https://www.guvenkaya.co/reports/sweat-booster#guv-5)

Medium Fixed

### Double claiming during account migration

The [**Sweat Jars Migration and Refactor**](https://www.guvenkaya.co/reports/sweat-jars-migration) review identified a medium-severity race condition.

State-changing functions in the old contract did not check whether the user’s account was migrating. Before the migration callback deleted that account, an attacker could claim rewards from the old contract and then claim them again from the new one.

The team fixed the issue by adding the account-migration check to state-changing functions.

- [GUV-1 Sweat Jars Migration & Refactor Smart Contract Review](https://www.guvenkaya.co/reports/sweat-jars-migration#guv-1)

High Fixed

### Storage accounting in the SWEAT token contract

The [**SWEAT NEP-141 Token**](https://www.guvenkaya.co/reports/sweat-token) review identified a high-severity issue in the custom `LookupMapAdapter` that could undercharge storage for selected accounts.

The review also covered governance permissions, deferred minting, pause controls, fee calculations, and event emissions. Of its 11 findings, **10 were marked fixed**. One informational finding concerning overlapping deferred batches after rollback was acknowledged.

- [GUV-1 SWEAT NEP-141 Token Security Review](https://www.guvenkaya.co/reports/sweat-token#guv-1)

### Calculation and state-handling issues

Other findings addressed scores not being restored after failed transfers, fee rounding, arithmetic overflow, APY interpretation, and Booster lifecycle behavior.

These findings concerned specific contract behaviors that could produce incorrect records, unexpected calculations, or failed operations.

## Supporting the team’s next steps

On 1 October 2026, the Sweat Foundation [announced](https://update.swe.at/) that Sweat Wallet and its current SWEAT offering would wind down on 30 December 2026. The token itself will continue to exist on-chain. The Foundation is exploring whether the app and token can continue in a new form, but has not committed to a relaunch.

We’re grateful to the Sweat Economy team for trusting us with this work over more than two years. We’ll always be here to support the team in the next evolution of the project, whatever form it takes.

![Guvenkaya](https://www.guvenkaya.co/favicon.svg)

## Guvenkaya

[Meet the team](https://www.guvenkaya.co/about#team)

## About Sweat Economy

- Industry

  Move-to-earn

- Chain

  NEAR

- Stack

  Rust smart contracts

- Service

  [Smart Contract Reviews](https://www.guvenkaya.co/services/smart-contract-security-review)

## Table of Contents

- [Engagement Dashboard](#engagement-dashboard)
- [About Sweat Economy](#about-sweat-economy)
- [What we reviewed](#what-we-reviewed)
- [Key findings](#key-findings)
- [Supporting the team’s next steps](#supporting-the-teams-next-steps)

## Share

[Share on X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.guvenkaya.co%2Fcase-studies%2Fsweat-economy\&text=Sweat%20Economy%3A%20More%20than%20two%20years%20of%20security%20reviews) [Share on LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fwww.guvenkaya.co%2Fcase-studies%2Fsweat-economy) [Share on Threads](https://www.threads.net/intent/post?text=Sweat%20Economy%3A%20More%20than%20two%20years%20of%20security%20reviews%20https%3A%2F%2Fwww.guvenkaya.co%2Fcase-studies%2Fsweat-economy)

[Discuss a security review](https://www.guvenkaya.co/contact?source=case_study)

Related services

## How we can help

### [Smart Contract Security Reviews](https://www.guvenkaya.co/services/smart-contract-security-review)

Find flaws in contract logic, permissions, accounting, and upgrades before they put funds at risk.

- Permissions & accounting
- Protocol logic
- Integrations

Explore

### [Blockchain Protocol & Infrastructure Reviews](https://www.guvenkaya.co/services/blockchain-protocol-security-review)

Review custom chains, runtimes, nodes, consensus, and bridges beneath the application layer.

- Custom chains
- Runtimes & VMs
- Nodes
- Consensus

Explore

### [Cryptography Reviews](https://www.guvenkaya.co/services/cryptography-security-review)

Review ZK circuits, custom primitives, signature schemes, privacy protocols, and post-quantum designs before you build on them.

- ZK circuits
- Primitives & schemes
- Post-quantum

Explore

[View all services](https://www.guvenkaya.co/services)

## Tell us what you need to secure.

Describe your system, main concern, and deadline. We’ll reply with scoping questions and a proposed next step.

[Discuss your scope](https://www.guvenkaya.co/contact?source=case_study)
