Introducing Blockchain-as-a-Service for Institutions and Enterprises. Learn more
Contact us
Covered ArcX's vault, orderbook, and cross-chain bridging contracts that split yield tokens into Strategy and Exchange Points tokens, including the CCTP-based bridge routing capital to Wildcat lending markets on Ethereum.
Assessed Bloxchain's role-based access control system, covering time-delay and meta-transaction execution paths and the RuntimeRBAC permission model.
Covered the PrimeStakedXDC_V3 ERC4626 vault and its V2-to-V3 migration bridge, spanning validator delegation, withdrawal queues, and share migration, across two audit stages.
Examined the LMSR-based AMM, operator-matched orderbook, multisig-controlled market resolution, and factory-deployed market clones. Given the volume of issues found, an additional review before deployment was recommended.
Looked at the minting and redemption flow, the StakedTrUSD yield vault, and the LayerZero-based omnichain expansion of trUSD across chains.
Focused on the UWattsVault4626 vault, its staking strategy, and the Superfluid-based real-time reward distribution mechanism.
Compared the EtherPool and Merkle Tree with History contracts against their Solana equivalent, looking for constraint differences and EVM-specific risk.
Checked the RoycoVaultMakinaStrategy integration layer allocating and redeeming assets between the Concrete vault and a dedicated Makina Machine.
Went through the File Manager package end to end, investigating permissions and secret management
This review covered the new MellowAccountV1 curator smart account added to Mellow's flexible-vaults system.
Scope centered on the redeem queue module governing how withdrawal requests are processed.
Covered the cryptographic core: secret sharing, distributed proof generation, and the oblivious PRF producing unlinkable nullifiers.
Focused on the V2 core contracts, specifically the logic changed since V1.1.
Scope was the new BurnableTokenizedShareManager contract, which lets users voluntarily burn share tokens to reduce supply.
Covered end-to-end changes to World's nullifier contracts.
Examined the CoveredMetavault contract, an insured ERC-4626-compatible yield vault implementing the ERC-7540 async deposit/redemption lifecycle.
Reviewed the SyncDepositQueue contract, which processes deposits synchronously against the latest oracle report.
Covered the UUPS-upgradeable ERC20 gold token: issuance/redemption workflow, transfer fee, and regulatory blacklisting.
Covered the core staking contract, token implementation, vesting utility, and slashing mechanism for misbehaving nodes.
Assessed changes to Celo's op-succinct and Celo-kona components as part of the Hokulea integration.
Examined the SwapModule contract, which executes permissioned token swaps for Mellow subvaults via DEX aggregators or CoW Protocol.
Covered the OracleSubmitter adapter, a Chainlink-compatible price feed interface for Mellow's main Oracle contract.
End-to-end changes to Anoma's Resource Machine and EVM Protocol Adapter were the focus of this review.
Covered the core StakedMonad contract: deposits, the two-step withdrawal queue, batch processing, and reward compounding.
Focused on the MultiATM contract, an oracle-priced atomic token swap machine supporting multi-hop swaps and meta-transactions.
Covered the vault's LP deposit and yield system, ERC-4626 integration, market-maker slashing protections, and dynamic fee structure.
Examined the OnchainCLOB and Trie contracts: order management, asset custody, and the radix trie order-matching structure.
Covered transaction batching, gas fee sponsorship, cross-chain owner sync, and signature validation features.
Covered the Compounding Staking Strategy's validator lifecycle management, SSV-based distributed validation, and Merkle-proof balance verification.
The Migrator contract, which automates moving assets from legacy MultiVaults into Mellow's new core vault system, was the focus.
Covered the Genesis staking contracts and their HIP-3 successor: the vHYPE liquid staking token, batched withdrawals, and a slashing mechanism, across two review phases.
Examined the core contracts converting ecological impact into digital credits redeemable for tokens.
Covered the TruStakePOL vault contract, deployed behind a transparent upgradeable proxy.
Examined the on-chain swap contracts combining Uniswap Universal Router, Hyperlane cross-chain messaging, and ERC-7579 accounts.
Covered the kernel-periphery architecture across EVM chains and Solana, including the off-chain executor relay that settles cross-chain swaps.
Differential audit of code changes since the prior NM-0563 review, focused on moving constructor logic into initializer functions.
The core protocol contracts were in scope: Vault, Subvault, deposit/redeem queues, Oracle, Verifier, ShareManager, FeeManager, and RiskManager.
Covered the lock-and-mint bridge contracts moving assets between Starknet L2 and Appchain L3 networks, modeled on the StarkGate L1-L2 bridge.
The MoleculaSuppliedWrapper contract was the focus, looking at the wrapping and unwrapping mechanisms.
Covered the ten core contracts behind USPD's dual-token architecture, including Stabilizer and Position NFTs, liquidation logic, and cross-chain bridge escrow.
Covered two interconnected ERC4626 vaults: the primary strategy vault and the liquidity-bootstrapping LP vault.
Examined the Inbox contracts handling batch proposition, proof submission and verification, and conflicting state transition handling.
Covered the SP1 Accounting Report contract, its zkVM circuit, and deployment scripts, which prove and store state changes between Lido oracle reports.
Diff audit of Clagg's refactored adapter architecture, covering the new Swapper contract and ERC4626-based Morpho and Spark integrations.
The newly added sponsored-execution function of AVNU's Paymaster forwarder contract was the focus.
Scope was a new Action Verifier for Incentiva campaigns and minor changes to the IncentiveLocker contract.
Covered the Appchain contract managing L3 state and cross-layer messaging, and the off-chain Orchestrator generating and submitting state-transition proofs.
Covered the Rollup Boost service enabling permissionless block building outside the Sequencer's execution engine, and its implications for OP Stack chains.
Covered the integration of Magna's claim-and-stake hook with Skate, auto-staking claimed funds into EigenLayer, plus post-deployment verification of the OFT Skate token across Ethereum, Binance Chain, and Solana.
Covered the Cairo contracts minting and burning iBTC on Starknet against Bitcoin deposits confirmed via Discrete Log Contracts.
The vesting and reward wrapping mechanism, which releases WSophon rewards to participants over time, was in scope.
Covered the Transaction Proxy Relayer's pass-through validation logic across three builder back-ends.
Examined the World Chain Builder's priority blockspace mechanism for Priority Blockspace for Humans (PBH) transactions.
Covered the refactored DLP incentive code normalizing off-chain performance data and distributing epoch rewards via on-pool swaps.
The Worldcoin Vault's interest accrual logic and its integration with the WorldIDAddressBook verification registry were in scope.
Covered the OperatorPayoutsWorldchain contract converting USD-denominated rewards into WLD token payouts.
Scope was a pull request adding synchronous deposits and a burn function to Lagoon's Gnosis Safe and Zodiac Roles Modifier-based vault factory.
Covered the L2 bridge contracts letting users deposit into Renzo from Layer 2 networks for the L2 equivalent of ezETH.
The new Data Access System components were in scope: data refinement, the query engine, and the compute engine.
Covered the Incentive Locker, the core contract connecting Royco Boosts' reward campaign system.
Renzo's core protocol contracts were the focus, ahead of EigenLayer's slashing update.
Covered VanaPool, a new staking mechanism letting users stake VANA tokens into community-managed entities with configurable APY.
Covered the contracts governing fractional car ownership, rental profit sharing, and eventual sale proceeds.
The Origami vault's tokenized balance sheet, LTV optimization, and cross-chain bridging of vault shares via LayerZero were in scope.
Covered Cooler V2's perpetual position model, unified user positions, governed LTV growth, and collateral vote delegation.
Covered the PBH entrypoint contract, EIP-4337 signature aggregator, and modified Safe Account module.
The integration of VeVana, a vote-escrowed ERC20 wrapper on top of the native Vana token, was in scope.
Scope was a pull request updating the Cairo compiler version and adding Chainlink-related interfaces to the unlocker, chainlink, and futureToken contracts.
Covered Veggia's free and paid minting tiers, cap plans, and NFT royalty and burn mechanics.
Covered the staking contracts (locked and unlocked modes), voting-token minting on stake, and the ZDAO governance.
Covered the Singleton Paymaster's two sponsorship modes: off-chain balance-based and ERC-20 token-based gas payments.
Covered the DLPRoot contract split into multiple contracts for bytecode size, plus new DLP whitelisting and staking reward multiplier rules.
The BoringChef contract, which manages reward epochs and user balance tracking, was in scope.
Covered the new LayerZero-based cross-chain integration bridging KING between Ethereum mainnet and Swell Chain.
The new IP Asset restaking functionality added to Verio was the focus.
Covered the Shiva position-management layer plus a core Overlay pull request adding a liquidation callback, including a mid-review nonce management change.
Covered MetaPool's integration with Story Protocol: native and wrapped IP token deposits, validator staking, and the 14-day withdrawal period.
The core Verio liquid staking system implementation was the focus.
Covered the GaiaNet token and time-locked governance contracts.
Covered the WorldIDIdentityManagerImplV3 update enabling compressed proof verification via the Semaphore Verifier.
Covered Canary's two staking vault contracts under active development.
Covered a new feature letting depositors prove and withdraw funds on the destination chain via Merkle proofs.
Covered the Data Registry, Data Liquidity Pool validation via Trusted Execution Environment, and Data Access Token governance.
Covered the Circom circuits underpinning DOP's private transfer and selective-disclosure system.
Every audit follows the same process, and you work directly with the auditors reading your code.