Skip to content

Latest commit

Β 

History

48 Commits

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

🏦 Secure Crowd Fundinng Protocol (Foundry Edition)

A production-oriented crowdfunding smart contract built with Foundry, designed to handle real-world fund flows securely and predictably.

This project goes beyond basics β€” it demonstrates:

  • Secure ETH handling πŸ”
  • Deterministic state machine design βš™οΈ
  • Fee-based economic modeling πŸ’°
  • Audit-aware development mindset πŸ›‘οΈ

πŸ“š Table of Contents


πŸ’Ό Why This Project Stands Out

Most crowdfunding contracts stop at β€œfund & withdraw”.

This protocol implements:

  • βœ… State-driven lifecycle (ACTIVE β†’ SUCCESS β†’ FAILED)
  • βœ… User refunds with fee logic
  • βœ… Owner withdrawals with platform fees
  • βœ… USD-denominated funding via Chainlink
  • βœ… Security patterns (CEI + Reentrancy protection)

πŸ‘‰ Built as a real DeFi primitive, not a demo.


πŸ“ Project Structure

β”œβ”€β”€ src/              # Core smart contracts
β”œβ”€β”€ script/           # Deployment & interaction scripts
β”œβ”€β”€ test/             # Unit & edge-case tests
β”œβ”€β”€ lib/              # External dependencies
└── foundry.toml      # Foundry configuration

βš™οΈ Getting Started

Requirements


Clone & Build

git clone https://github.com/barnabasmunuhe/Secure-Crowd_Funding-Protocol
cd fund-me
forge install
forge build

πŸš€ Deploying Contracts

πŸ§ͺ Local Deployment

forge script script/DeployFundMe.s.sol \
  --fork-url http://127.0.0.1:8545 \
  --broadcast \
  --private-key <PRIVATE_KEY>

🌐 Testnet Deployment (Sepolia)

forge script script/DeployFundMe.s.sol \
  --rpc-url $SEPOLIA_RPC_URL \
  --private-key $PRIVATE_KEY \
  --broadcast \
  --verify \
  --etherscan-api-key $ETHERSCAN_API_KEY

πŸ§ͺ Running Tests

Unit Tests

forge test -vvv

Forked Tests

forge test --fork-url $SEPOLIA_RPC_URL

Coverage Report

forge coverage

🧠 Core Contract Logic

πŸ”„ State Machine

ACTIVE β†’ SUCCESS β†’ FAILED
  • ACTIVE β†’ users can fund
  • SUCCESS β†’ owner can withdraw
  • FAILED β†’ users can refund

πŸ‘‰ Ensures predictable and secure behavior.


πŸ’° Fee Model

  • Platform Fee β†’ applied on withdrawals
  • Refund Fee β†’ applied on user refunds

βœ” Implemented using basis points (BPS)
βœ” Eliminates floating-point precision errors


πŸ” Security Considerations

  • Reentrancy protection (ReentrancyGuard)
  • Access control (Ownable)
  • Checks β†’ Effects β†’ Interactions (CEI)
  • Pull-based refund pattern
  • No gas-heavy loops

πŸ”— Chainlink Integration

Uses Chainlink Price Feeds to:

  • Convert ETH β†’ USD
  • Enforce minimum contribution threshold
  • Stabilize funding logic

πŸ“œ Example Interactions

Fund Contract

cast send <FUNDME_ADDRESS> "fund()" \
  --value 0.1ether \
  --private-key <PRIVATE_KEY>

Withdraw (Owner Only)

cast send <FUNDME_ADDRESS> "ownerWithdraw(uint256)" \
  --private-key <PRIVATE_KEY>

Refund (User)

cast send <FUNDME_ADDRESS> "refund()" \
  --private-key <PRIVATE_KEY>

πŸ§ͺ Testing Philosophy

This project focuses on behavior-driven testing, including:

  • Funding validation
  • Refund correctness (with fee deduction)
  • Owner withdrawal accounting
  • State transitions
  • Edge cases (double refund, insufficient balance, etc.)

πŸ‘‰ Emphasis on financial correctness, not just coverage.


πŸ›‘οΈ Audit Awareness

During development, a critical bug was identified and resolved:

  • Incorrect refund transfer logic
  • Could lead to fund imbalance

βœ” Fixed with correct payout calculation

πŸ‘‰ Demonstrates audit-level thinking and debugging discipline


🧠 Concepts Covered

  • Fallback & receive functions
  • msg.value / msg.sender
  • Chainlink oracles
  • Access control patterns
  • Fee modeling (BPS)
  • Smart contract testing (Foundry)
  • Deployment scripting
  • Gas analysis (forge snapshot)

πŸ” Upcoming Enhancements

  • Campaign factory (multi-project deployment)
  • DAO-controlled treasury
  • ERC20 funding support
  • Milestone-based payouts
  • Emergency pause mechanism

🎯 What This Project Proves

This project demonstrates:

  • Real-world smart contract architecture
  • Secure financial logic implementation
  • Strong testing discipline
  • Awareness of production risks

πŸ‘‰ Ready for DeFi / Smart Contract Engineering roles


πŸ§‘β€πŸ’» About

Blockchain developer focused on:

  • Smart contract engineering
  • Protocol design
  • Security & testing

πŸ“Œ Notes

This is an evolving project focused on building production-grade Solidity systems.

Feedback, issues, and PRs are welcome.


🧠 License

MIT License


⭐ Support

If you find this useful, consider starring ⭐ the repo.


πŸ™ Acknowledgment

Built with focus, discipline, and a deep commitment to mastering smart contract engineering.

About

No description, website, or topics provided.

Resources

Stars

2 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages