A production-oriented crowdfunding smart contract built with Foundry, designed to handle real-world fund flows securely and predictably.
This project goes beyond basics β it demonstrates:
- Secure ETH handling π
- Deterministic state machine design βοΈ
- Fee-based economic modeling π°
- Audit-aware development mindset π‘οΈ
- πΌ Why This Project Stands Out
- π Project Structure
- βοΈ Getting Started
- π Deploying Contracts
- π§ͺ Running Tests
- π§ Core Contract Logic
- π Chainlink Integration
- π Example Interactions
- π§ͺ Testing Philosophy
- π‘οΈ Audit Awareness
- π§ Concepts Covered
- π Upcoming Enhancements
- π― What This Project Proves
- π§βπ» About
- π Notes
- π§ License
- β Support
- π Acknowledgment
Most crowdfunding contracts stop at βfund & withdrawβ.
This protocol implements:
- β State-driven lifecycle (ACTIVE β SUCCESS β FAILED)
- β User refunds with fee logic
- β Owner withdrawals with platform fees
- β USD-denominated funding via Chainlink
- β Security patterns (CEI + Reentrancy protection)
π Built as a real DeFi primitive, not a demo.
βββ src/ # Core smart contracts
βββ script/ # Deployment & interaction scripts
βββ test/ # Unit & edge-case tests
βββ lib/ # External dependencies
βββ foundry.toml # Foundry configuration
- Git
- Foundry
- Node.js & NPM
- Optional: Docker
git clone https://github.com/barnabasmunuhe/Secure-Crowd_Funding-Protocol
cd fund-me
forge install
forge buildforge script script/DeployFundMe.s.sol \
--fork-url http://127.0.0.1:8545 \
--broadcast \
--private-key <PRIVATE_KEY>forge script script/DeployFundMe.s.sol \
--rpc-url $SEPOLIA_RPC_URL \
--private-key $PRIVATE_KEY \
--broadcast \
--verify \
--etherscan-api-key $ETHERSCAN_API_KEYforge test -vvvforge test --fork-url $SEPOLIA_RPC_URLforge coverageACTIVE β SUCCESS β FAILED
- ACTIVE β users can fund
- SUCCESS β owner can withdraw
- FAILED β users can refund
π Ensures predictable and secure behavior.
- Platform Fee β applied on withdrawals
- Refund Fee β applied on user refunds
β Implemented using basis points (BPS)
β Eliminates floating-point precision errors
- Reentrancy protection (
ReentrancyGuard) - Access control (
Ownable) - Checks β Effects β Interactions (CEI)
- Pull-based refund pattern
- No gas-heavy loops
Uses Chainlink Price Feeds to:
- Convert ETH β USD
- Enforce minimum contribution threshold
- Stabilize funding logic
cast send <FUNDME_ADDRESS> "fund()" \
--value 0.1ether \
--private-key <PRIVATE_KEY>cast send <FUNDME_ADDRESS> "ownerWithdraw(uint256)" \
--private-key <PRIVATE_KEY>cast send <FUNDME_ADDRESS> "refund()" \
--private-key <PRIVATE_KEY>This project focuses on behavior-driven testing, including:
- Funding validation
- Refund correctness (with fee deduction)
- Owner withdrawal accounting
- State transitions
- Edge cases (double refund, insufficient balance, etc.)
π Emphasis on financial correctness, not just coverage.
During development, a critical bug was identified and resolved:
- Incorrect refund transfer logic
- Could lead to fund imbalance
β Fixed with correct payout calculation
π Demonstrates audit-level thinking and debugging discipline
- Fallback & receive functions
- msg.value / msg.sender
- Chainlink oracles
- Access control patterns
- Fee modeling (BPS)
- Smart contract testing (Foundry)
- Deployment scripting
- Gas analysis (
forge snapshot)
- Campaign factory (multi-project deployment)
- DAO-controlled treasury
- ERC20 funding support
- Milestone-based payouts
- Emergency pause mechanism
This project demonstrates:
- Real-world smart contract architecture
- Secure financial logic implementation
- Strong testing discipline
- Awareness of production risks
π Ready for DeFi / Smart Contract Engineering roles
Blockchain developer focused on:
- Smart contract engineering
- Protocol design
- Security & testing
This is an evolving project focused on building production-grade Solidity systems.
Feedback, issues, and PRs are welcome.
MIT License
If you find this useful, consider starring β the repo.
Built with focus, discipline, and a deep commitment to mastering smart contract engineering.