D7-01MediumAccepted
The redemption queue's per-epoch liquidity budget is read from a live balance and can be inflated with borrowed capital inside one transaction
The queue's per-epoch budget is snapshotted from an attacker-movable live balance, so borrowed capital can bypass the intended throughput cap. The mechanism remains PROVEN on a pinned mainnet fork with genuinely borrowed capital and is not remediated. Impact was re-rated from High to Medium on 3 August 2026: declared defaults immediately feed pendingSeniorImpairment(), and runbook section 7.5 requires an atomic private default declaration, so an exit after declaration is already priced at the impaired conservative NAV. What remains is run-dynamics harm from bypassing the throughput cap rather than the previously published targeted loss-avoidance channel. Forest Road formally ACCEPTED this residual Medium risk on 3 August 2026, conditioned on that atomic-private procedure and conservative-pricing behavior remaining in force. Revisit the acceptance if either control changes, the queue design changes, or new evidence establishes targeted extraction.
C-01MediumAccepted
A reserve write-down freezes minting, redemption AND all facility servicing, curable only by an unrehearsed emergency role grant
The backing check is an absolute post-state gate: it asks whether the end state is solvent, never whether the operation improved matters. The one lever the protocol provides for recording a stablecoin custody loss lowers recognized backing with no paired burn, so using the feature exactly as designed produces a state in which minting and redemption both revert. RE-RATED DOWN FROM HIGH, and both halves of that re-rating are substantive. Worse than first reported: the repayment path is exactly NEUTRAL on the shortfall rather than narrowing it, because both interest legs are minted — so this round's earlier claim that repayments would gradually heal the gap is arithmetically wrong, and while the system is under water the credit book cannot be serviced at all. Less severe than first reported: the claim that no on-chain recovery exists short of a contract upgrade is false. Two governance cures exist, each demonstrated restoring minting, redemption and servicing — recapitalize by the amount lost, or route the loss through the cascade as a senior haircut, which is what the cascade's own third layer already does. Forest Road ACCEPTED the fail-closed design on 3 August 2026 rather than relaxing the backing gate and allowing exits to race an acknowledged deficit. The acceptance is conditional on the production incident procedure: keep user operations paused and execute one timelock batch that grants itself temporary reserve-deposit authority, pulls the exact six-decimal USDC recapitalization from the Recovery Safe, and revokes that authority, followed by independent custody/backing/role verification before unpause. A reserve loss beyond available recapitalization or the protocol's clean cascade absorption capacity remains an escalation case rather than an ordinary recovery.
D4-01LowAccepted
The queue's anti-denial-of-service heartbeat guard is an absolute floor, so it is stepped over rather than overwhelmed
A guard exists specifically to stop an actor resetting the settlement clock by starving the queue of liquidity, but it is an absolute economic floor rather than a proportion of capacity. The mechanism remains PROVEN and no configuration change closes it. Impact was re-rated from Medium to Low on 3 August 2026: sustained denial requires a KYC-gated, visible and stoppable capital variant; the anonymous zero-capital variant produces a bounded, non-compounding one-epoch delay per inflow, extracts no value and creates no permanent freeze. Forest Road formally ACCEPTED this residual Low risk on 3 August 2026. The rejected demand-anchored fix must not be revived; revisit the acceptance if queue or epoch dynamics change or new evidence shows compounding, targeted extraction or anonymously repeatable sustained denial.
D5-03MediumOpen
A stale valuation disables every permissionless senior protection on a marked-to-market facility
The contract documentation states a deliberate asymmetry: protective triggers accept the latest mark at any age, while CURING a margin call demands a fresh one. The arithmetic does not implement that claim — the two protective paths gate on freshness identically to the curing path. Because the maturity-clock mechanism is additionally barred for marked-to-market classes, a mark that has simply gone stale leaves no permissionless senior protection at all. Measured: a facility sitting well above its margin threshold and materially underwater prices seniors at PAR, with the conservative exit valuation equal to the realized one, so a senior exiting through the queue in that window takes par and leaves the entire shortfall to those who stay. That is precisely the harm the mechanism was redesigned to prevent. Verification note, stated because it affects how much weight this carries: adversarial verification was capped at the two highest-severity findings per workstream and this one fell outside the cap, so it has no independent verdict. The cited lines were re-read against source by the engagement lead, but it is less hardened than the doubly-verified findings.
D12-01MediumOpen
An interest-only payment clears the on-chain clock but leaves the whole past-due impairment mark standing
The repayment path notifies the default manager that a facility is performing only inside the branch taken when principal is repaid, while the next-payment clock advances regardless. So an interest-only payment makes a facility no longer past due by the clock, yet the full mark-time impairment snapshot keeps depressing the conservative senior valuation until a servicer obtains an attested cure. Every queue settlement in that window underprices the seniors it pays. The mechanism was confirmed by both adversarial verifiers, who then split on impact, one rating it correct at High and the other Low; adjudicated Medium, because the mispricing is real and the window can be opened at will by an unprivileged caller — the past-due marking is permissionless — but it is bounded by the cure path and no profit extraction was demonstrated.
D9-01MediumOpen
The default administrator role administers the upgrade role, so the timelock is bypassable in a single grant
Reported as a CENTRALISATION RISK rather than folded into the severity ranking. Searching production source for a role-admin override returns nothing, so the default administrator role administers every role — including the upgrade role that the timelock is supposed to hold exclusively. Under the deployment posture that deliberately retains operator control, one grant converts operator control into upgrade authority with no timelock delay. THE MAIN PRODUCT OF THIS FINDING IS A CORRECTION TO THIS AUDIT'S OWN EARLIER PHASE, which examined live role assignments, found the upgrade role held only by the timelock on every module, and published the conclusion that no externally-owned account can upgrade anything. That conclusion is false as written: it described a configuration snapshot, not a control, and the safety specification's corresponding invariant does not hold as stated. An invariant campaign independently failed on this and shrank the counterexample to a single call. Both adversarial verifiers rated the RISK low on the ground that the posture is disclosed and deliberate, with a handover script that moves the roles to the timelock — a fair characterisation, and not a reason to leave a false published conclusion standing. Two further symptoms have the same single cause and should be remediated as one: the mint authority can be reconstituted the same way, which is separately documented by the team as a known consequence of the same posture. What is missing is not the mitigation but a named trigger for running it.
D9-03MediumOpen
The quorum denominator is total token supply while the numerator can only ever count delegated votes
Quorum is measured against total supply, but voting power only exists for tokens that have been delegated — a holder who never self-delegates counts toward the bar and never toward clearing it. As the token distributes to ordinary holders, quorum becomes progressively unreachable, and a stalled governor freezes every module parameter and every upgrade. Currently masked because genesis supply sits with the treasury, which can self-delegate and meet the bar. THIS INTERACTS WITH THE FINDING ABOVE IN A WAY THAT DICTATES REMEDIATION ORDER, and the interaction is not visible from either finding alone: the timelock bypass is presently the de facto escape hatch from a quorum stall. Closing the centralisation finding first — handing the administrator role to the timelock while the quorum defect stands — would make a stall UNRECOVERABLE, because the state that requires a governance action to fix would be the state that prevents one. The quorum denominator must be fixed first. Like the stale-mark finding, this fell outside the two-per-workstream verification cap and carries no independent adversarial verdict.
D-RATE-02MediumAccepted
Under severe declared impairment, an attested interest receipt can lower the senior exchange rate
The fee share minted against an inflow is sized so its value at the CONSERVATIVE valuation equals the fee, but the shares themselves are ordinary vault shares worth the REALIZED rate, so the dilution actually imposed is amplified by the ratio between the two. Past a threshold the amplification exceeds the benefit of the inflow itself and a payment made TO senior holders leaves them worse off. The threshold is exact and was pinned by test: the rate falls once the conservative valuation drops below the fee rate times the realized one — more than 90% of senior value under declared-but-unrealized impairment at the shipped fee, more than 80% at the rate cap. A control test confirms the ordinary case is unaffected: with no impairment live, the same receipt raises the rate. ACCEPTED BY FOREST ROAD ON 2 AUGUST 2026 on likelihood, not on correctness — the mechanism is not disputed. The rationale is recorded precisely, because the load-bearing condition is NOT the 90% impairment, which is more reachable than it sounds while concentration limits remain fully open and the book is thin. What makes the state hard to reach is the requirement for a large unpriced gain sitting above the high-water mark at the moment of the inflow, and fee crystallisation is permissionless and happens on entry, exit and repayment. The acceptance carries explicit revisit triggers: anything that lengthens the interval between fee checkpoints, a widening of the window inside the repayment path, a book that stays concentrated at scale, or a fee-rate increase toward the cap, which moves the threshold from 90% to 80%. One reachability step is NOT closed by the acceptance and is recorded as open work: the impairment was injected through a test double rather than driven through a real declared default, so what is proven is the arithmetic, not that the triggering state is reachable end to end.
A-02MediumOpen
The live attestation quorum provides no signer independence, and the attester is also the servicer
Reported as a CENTRALISATION RISK. The oracle proves signer distinctness by requiring recovered addresses to strictly ascend — a check on addresses, not on key custody, satisfied by two addresses derived from one seed and held by one party. The deployed configuration is exactly that degenerate case: the threshold equals the attester count, one attester is the deployer, and the project's own manifest records the second as derived from the deployer's key. The same key simultaneously produces the facts, acts on them as servicer, mints the position they gate, and administers the attester set. Two consequences were proven: the m-of-n control is satisfiable by one actor in one transaction, recording a valuation that feeds the solvency check; and because the threshold equals the set size there is zero fault tolerance, so losing a single key makes every high-value attestation kind unsatisfiable and halts the credit lifecycle. Rated against a mainnet launch carrying this configuration forward, which is the migration risk the deployment-reconciliation phase exists to catch; the posture is declared rather than concealed on the current testnet.
C-03LowOpen
A reversible impairment assessment crystallises irreversible performance-fee dilution of senior holders
Publishing an assessment lifts the fee valuation against an unchanged high-water mark; the next fee crystallisation books that lift as performance, mints fee shares and ratchets the mark. The assessment is time-boxed and lapses on any change to the underlying risk state, at which point the valuation falls back — but the minted shares are not clawed back and the mark does not un-ratchet. So a reversible, explicitly time-limited estimate produces permanent dilution, and if the assessed recovery never arrives, seniors have paid a performance fee on cash that never existed. PROMOTED FROM HYPOTHESIS TO PROVEN in this round, and RE-RATED DOWN from Medium at the same time. The escalation path the finding itself named — whether an administrator can cycle assessments to ratchet the mark repeatedly — was run as an experiment and DISPROVED: the cycling is bounded. Reporting the disproof of one's own escalation is the discipline the engagement asks for and it is recorded as such. What survives is a genuine asymmetry between who bears estimate risk and who captures estimate upside, requiring an administrator key and producing no external-attacker path.
C-02LowBy design
The permissionless reserve reconciliation is an unguarded, unpausable reduction of recognized backing
The reconciliation carries no role check or pause guard and ratchets recognized backing only downward. Forest Road classified that as BY DESIGN on 3 August 2026: the caller cannot move USDC, manufacture a shortfall or raise backing; any address may merely force the internal ledger to acknowledge a lower live canonical-USDC balance so a real custody loss cannot be hidden from depositors. Enumeration against canonical USDC at a pinned mainnet block found no issuer seize, clawback, burn-from or wipe primitive, so the external trigger is not reachable today. If USDC ever gains such a primitive, issuer action can expose a deficit and reconciliation will make the protocol fail closed, invoking the accepted C-01 recapitalization procedure. Direct transfers deliberately cannot reverse the ledger. The no-op event remains a low-cost indexer-spam nuisance and should be filtered by consumers; it does not change backing.
A-01LowOpen
The timelock implementation contract was left uninitialised and is permissionlessly seizable
Seventeen of eighteen implementations lock their initialiser in the constructor; the timelock does not, because it is the only implementation taken from an upstream library rather than written in-repo and it never received the house convention. Anyone may initialise it directly and take administrative control of the implementation contract. Bounded honestly, and deliberately NOT rated higher: every protocol role is granted to the timelock PROXY, whose storage is initialised and untouched by this, so the attacker gains no authority over any module, and the contract is not upgradeable so the usual escalation to bricking the proxy is unavailable. What remains real is that value misdirected to the implementation address is seizable — a realistic operator error, since it is a verified contract labelled as the timelock — and that an attacker-controlled contract at that address can emit genuine-looking governance events that an explorer or indexer may attribute to the protocol. It reaches mainnet unchanged unless the deployment script is fixed.
D-RATE-01LowOpen
The performance-fee high-water mark re-anchors after the fee is taken, so denser checkpoints charge more on the same gain
The mark is re-anchored to the rate AFTER fee shares are minted, so the next checkpoint measures profit from a mark below the rate the vault actually reached and charges a fee on the fee. Crystallisation is permissionless and takes no arguments, so its frequency is chosen by whoever wants to choose it — including the fee recipient. Measured on a fixed gain with management fees disabled: the effective rate rises from 999 basis points at a single checkpoint to 1083 at two hundred, against a mathematical limit of 1112, with the senior holder losing about 0.84% of the gain purely to checkpoint timing. Governance has no parameter that bounds this. The equivalent claim for the management fee was tested as a control and is CORRECT — that fee is genuinely frequency-neutral, and the decision record only ever claimed neutrality for it.
D3-01LowOpen
Two windows leave every vault conversion view readable at a transient wrong rate
The transient lock that defends against reading a half-applied fee rate covers one window and CREATES a divergence in another: on a plain share transfer it suppresses the fee simulation and quotes the gross, pre-fee rate. A second and larger window exists because the underlying vault standard burns shares before transferring assets, so a callback firing between the two observes a supply that has already fallen against assets that have not yet moved. Measured, the conversion views read a rate inflated by roughly three orders of magnitude inside that window. No internal consumer reads inside it, and installing an observer requires an administrator key, which is why this is Low rather than higher — but any external protocol that prices this share as collateral off the public views is exposed, so it is published as an integrator warning as much as a defect.
D5-01LowOpen
The staking reward stream strands value when total stake reaches zero mid-stream
Notifying rewards pulls value in and increments no accounting field; its only claim on that value is the streaming index. When total stake reaches zero the index stops advancing while the clock does not, so every second with nobody staked consumes stream time and credits it to nobody. The written-off value then sits outside the coverage reserve, so it can neither be claimed by stakers nor delivered by the loss cascade. Measured worst case, a full notification abandoned immediately strands 100% of it. The word PERMANENTLY was refuted by both verifiers and is not claimed here: the contract is upgradeable and the timelock holds the upgrade role, so a governance upgrade recovers it. Also note the notification entrypoint is permissionless.
D11-01LowOpen
The emergency valuation-source recovery cannot fire on the failure mode it exists for
The install-time probe of an untrusted valuation source is gas-bounded and cannot be exhausted, but the PRODUCTION read of the same source calls it through the ordinary interface, which copies the whole return buffer into memory. Memory expansion is quadratic, so a source returning a large payload turns every exit-pricing read into a gas bomb — measured at more than five times the block gas limit, meaning not expensive but unexecutable — while the bounded probe that is supposed to detect an unreadable source still reports it healthy. The install gate and the recovery gate should use the same budget, so that a source which installs is a source the emergency clear will later agree is broken.
D11-02LowOpen
A repayment-path fee recipient is not checked for compliance exemption, unlike its vault sibling
The vault enforces twice that its fee recipient is protocol-exempt before accepting it; the repayment engine's equivalent setter enforces it not at all. A fee recipient that is later sanctioned by the compliance registry therefore causes every repayment on every facility to revert, because the fee leg cannot be delivered. Small change, and the asymmetry between two siblings is the kind of gap that survives review precisely because each side looks reasonable alone.
D11-03LowOpen
Flooding the redemption queue imposes a measured gas amplification on the keeper of the sole exit
Each settlement iteration recomputes conservative pricing per request, so clearing the queue costs the keeper more than filling it costs an attacker — measured at 1.82x across forty minimum-value requests. Strict first-in-first-out with no cancellation path and no reordering means the keeper cannot skip the flood. This is a cost asymmetry rather than a block-limit break, which is why it is Low: the queue still settles. Caching the per-settlement price rather than recomputing it, or a refundable deposit per entry, closes the instance; the general shape — cheap to enqueue, expensive to settle — needs an economic answer.
D9-04LowOpen
The timelock is an unfixable governance root whose only escape route runs through itself
Reported as a governance-structure risk. The timelock sits behind a plain proxy over a non-upgradeable implementation, so the governance root cannot be upgraded. Repairing a defect in it therefore requires migrating every module's upgrade role, and that migration must itself be authorised by the timelock that is broken. Measured in the production posture: none of the sixteen modules can have its upgrade role re-pointed without a working timelock. This is very likely a deliberate design — an immutable root is arguably the safer choice — but it is nowhere documented as one, and there is no on-chain storage-layout guard on the upgrade such an escape would require. Note the interaction with the role-admin finding above: today the administrator bypass is the de facto escape hatch.
D12-05LowOpen
The loss-burn entrypoint accepts an arbitrary holder and the token burn performs no allowance check
Reported as a CENTRALISATION RISK, not as an external-attacker path. The burn used by the loss cascade takes a caller-chosen address, and the token's burn checks only the minter role — no allowance, no ownership. The cascade itself only ever needs two targets, so the parameter is far wider than any real caller requires, and a single compromised credit-role key drains any holder to zero in one call. The backing check cannot object, because burning only improves it. Narrowing the parameter to the two known targets closes it.
D13-01LowRemediated
The blocking static-analysis gate certifies green on an analysis that covered only part of the tree
One of four ASSURANCE-CHAIN defects, and they share a property worth stating once: each was a CONTROL THAT FAILED OPEN, so every earlier green result was worth less than it appeared — including results this audit itself leaned on. The first remediation bound reports to the complete production source list and source digest and rejected compile failures. A second-pass review found one remaining bypass: Slither could still auto-load a repository configuration that filtered paths or detectors. REMEDIATED 3 AUGUST 2026: the runner now supplies its own empty configuration, records the exact fixed analysis profile and configuration digest, and the checker rejects any missing or changed attestation. A tracked CI regression drives the real runner through a hostile fake analyser that accepts only that private empty config, and separately proves metadata tampering is rejected.
D13-02LowRemediated
The upgrade-safety storage gate covers 18 of 26 layout-critical structures
Storage COLLISION is structurally impossible here — every module uses namespaced storage and there is no sequential layout to collide, which was proven rather than assumed. But reordering fields WITHIN a namespace still corrupts a live proxy, and this gate is the control for that. REMEDIATED 3 AUGUST 2026: balanced-brace parsing and recursive type-graph discovery now cover all 26 reachable namespaced, embedded, array-element and mapping-value structures; declaration comments no longer affect discovery; complete mapping types are retained instead of erasing unnamed key types; and a structure reused in multiple contexts inherits the strictest relation. Tracked CI regressions mutate a mapping key from address to bytes32 and reuse a namespaced structure as an array element, requiring both unsafe cases to be detected.
D13-03LowRemediated
The broadcasting QA script lets an environment variable choose which deployment it drives, unbound to the connected chain
The read-only validator gained a chain-versus-manifest assertion; the script that actually signs and broadcasts did not, though it has strictly more blast radius. A stale shell export while the endpoint points elsewhere could therefore target addresses from an unrelated deployment. REMEDIATED 3 AUGUST 2026: QA now resolves a canonical manifest for the connected chain, checks the manifest chain ID before any transaction, and asserts every configured address against that receipt. Six focused Foundry tests cover the canonical binding, wrong-chain and wrong-address rejection, and the permitted explicit local-fork override. This is an operator-safety remediation rather than a protocol change.
D13-04LowRemediated
The frontend fee-ABI version guard is inverted and now fires only for the safe pairing
The guard exists to stop a vault lacking the current fee interface being driven with current fee selectors. After a default was flipped, it fired only for the combination that was already safe, leaving the dangerous pairing unguarded. REMEDIATED 3 AUGUST 2026: an explicit vault can no longer inherit an unrelated fee-ABI default; known archived and current addresses are checked in both directions; and an unknown test deployment must state its ABI version explicitly. The deployment manifest remains the default source. Seven resolver regressions cover default, archived, current, case-normalized and invalid-version combinations, and the contract/UI synchronization suite exercises the resulting ABI.
D6-01InformationalOpen
The vault prices and ratchets against a donated balance while total supply is zero, and the seed is not atomic with initialisation
The degeneracy guard short-circuits whenever supply is zero, on the reasoning that there are no incumbents to harm — true when assets are also zero, but the branch does not require that, so it equally admits a vault that has been donated into. In that state the empty-supply branch of fee accrual ratchets the high-water mark to an arbitrary height permanently, and the per-deposit rounding floor degrades by many orders of magnitude. The deployment wraps its phases in one broadcast but emits one transaction per call, so the vault is live and empty for roughly sixty transactions before the anti-inflation seed lands. Informational rather than higher because the attack is unprofitable in every variant tested — the attacker loses the entire donation and, in the first-depositor variant, far more than the victim. The recommended fix is a deploy-time assertion rather than a contract change.
D11-04InformationalOpen
Permissionless checkpointing permanently allocates storage for any never-participating address
Confirmed AND CORRECTED against the carried claim. Checkpointing writes accrual state for two token positions and all five class positions of an arbitrary address regardless of balance, so calling it for a fresh address permanently allocates seven slots that nothing reclaims. But the measured cost is 0.87x the raw storage-write cost, so it is NOT a state-bloat amplifier — an attacker pays more than they impose — and it degrades no dependent path. Guarding the writes on a non-zero balance is a small improvement rather than a fix for a live risk. Recorded because the original claim overstated it and the correction is the useful part.
D3-05InformationalOpen
Correction to this round's own record: the points hooks do make an outbound call
An earlier phase of this same audit dismissed reentrancy through the transfer hooks partly on the ground that the hooks make no outbound calls at all, so there is nothing to re-enter through. That is wrong: both hooks call an exclusion check that reaches a separately deployed, administrator-configurable contract, up to twice per invocation, proven with an explicit call expectation. The dismissal still stands, but for a weaker and more fragile reason — the call is a read-only static call and cannot mutate. Published because an argument stated more strongly than the code supports will be relied on by the next reviewer and by whoever writes the next module.
D3-02InformationalOpen
Two loss-path points hooks swallow failures with no telemetry, unlike their siblings — the larger claim around it was refuted
Published as a REFUTED finding reduced to what survives, because a register that shows only successes is not a record. The original claim was that a silently dropped hook durably defeats an accrual freeze and produces a large points over-accrual; both adversarial verifiers refuted it on the same ground, that the test's module never actually reverts in the relevant hook, so the silent catch is never entered and the test demonstrates an administrator swapping in a no-op module rather than a swallowed failure. The confidence label was not earned for the stated mechanism. What survives and is worth fixing: two catches on the loss path genuinely lack the failure event that the two token-side catches both emit, so a dropped accrual there is unobservable off-chain.
What this round was
Every previous round on this register reviewed a change. This one reviewed the protocol, under a
formal engagement protocol written before any code was read, with a single instruction: break it.
The protocol had five phases and each had to finish before the next began. Reconcile what is
actually deployed against the source. Derive a threat model from the code rather than from the
documentation. Sweep a mandatory vulnerability-class table where every class owes either a finding
or a written reason it does not apply. Attack it on two pinned forks. Then report.
Three rules mattered more than the rest. Source was frozen through discovery — nothing was
fixed while anything was still being looked at, because repairing as you go contaminates everything
you look at afterwards and destroys the record of what the code was when the bug was found. Every
finding above Informational owes a test that actually runs, and a finding without one is labelled
a hypothesis rather than dressed up as a result. And a dismissal owes a test too: if you believe
a function is safe from reentrancy, you write the test that tries it, because a clean report is the
easiest place in the world to hide an untested assumption.
The core mechanics held
This is the most important result and it is a measured one, not a courtesy.
The three-layer loss cascade was attacked directly and did not break. Ordering, conservation and
subordination headroom all held across 163,840 stateful calls with independently tracked ghost
capacities — and, for the first time, with the per-event backstop cap exercised at a value that
actually binds. A previous round had found that this cap had no callers anywhere in the test
suite, so the layer-2 rule had never been tested at a value where it constrains anything. It has
now been.
The redemption queue's solvency, its strict first-in-first-out ordering, its no-double-claim
property and its liveness all held across another 163,840 calls, including under chunked
settlements, forty-five-day keeper absences, and liquidity drained to zero and refilled.
The attestation layer held under a deliberate assault: zero-address recovery, signature
malleability, compact and legacy signature encodings, bundle-ordering attacks, replay across kinds
and facilities and payloads and chains, and the valuation anti-rollback watermark. This layer
matters more here than in most protocols, because the system integrates no on-chain price oracle
at all — there is no AMM, no price feed, no TWAP. The entire price-manipulation family of attacks
has no surface, and the equivalent risk is relocated wholly into attestation.
Reentrancy was closed across all six sub-classes — and closed by building a hostile module and
installing it, not by reasoning about the call graph. Every unchecked block, every downcast and
every assembly site was proven safe for all reachable inputs. Rounding direction was enumerated
across every division in four contracts.
And flash-loan atomicity was tested by actually borrowing, at a pinned block, from a real
lending pool with real depth — never by simulating a balance. Seven of the nine state-dependent
surfaces resisted, including governance voting power and the backing invariant's computed side.
Where it broke: two clusters, not a scatter
The failures are not distributed. They sit in two places, and saying so is more useful than a
severity ranking.
Economic controls derived from spot-read balances. The queue's per-epoch liquidity budget is
read from a live balance at the instant settlement opens, and a live balance can be moved inside a
single transaction with borrowed capital. That budget is the protocol's only throttle on senior
exits. Separately, the guard protecting the settlement heartbeat is an absolute constant rather
than a proportion of the epoch's actual capacity — so it does not need to be overwhelmed, only
stepped over, and stepping over it costs about a dollar. Both of these attack the only exit the
senior claim has.
The role-admin topology. Searching the production source for a role-admin override returns
nothing, which means the default administrator role administers every role. Under the deployment
posture that deliberately retains operator control on testnet, that one fact produces three separate
symptoms that had been filed as three findings: the timelock can be bypassed in a single grant, the
mint authority can be reconstituted, and two of the safety specification's own invariants turn out
to describe a configuration snapshot rather than a property. They should be remediated as one thing.
An audit that corrected itself four times
The most useful thing this round produced was not a finding. It was four corrections to conclusions
this same audit had already published in its earlier phases.
The sharpest: an earlier phase found that a reserve write-down freezes minting and redemption, rated
it High, and recorded that repayments would gradually heal the shortfall. Working it through on a
funded facility showed that reasoning is arithmetically wrong — the repayment path is exactly
neutral on the gap, not narrowing, so while the system is under water the credit book cannot be
serviced at all. That makes the mechanism worse than reported.
The same work then found the opposite error in the same finding. It had claimed no on-chain
recovery exists short of a contract upgrade. Two governance cures do exist, each demonstrated
restoring minting, redemption and servicing. The finding came down from High to Medium and was
reframed from an unrecoverable brick to an incident-response gap — a real gap, because the cure
requires a role grant the deployment script never makes and nobody has rehearsed.
Its recommended fix was also struck, because the decision record shows that exact change was
already considered and rejected for a good reason: it would invert the loss cascade, letting exits
race while the protocol is impaired and subordinating the holders who stay.
An audit that cannot correct itself is worth less than one that can, so all four corrections are in
the report rather than quietly patched.
The coverage result, stated against itself
The production source measures 100% of lines, statements, branches and functions under the
repository's own test suite. That was measured, and then independently re-measured.
Every defect in this report lives in code that is fully covered.
That is the point, and it is why the number is published next to the findings rather than instead of
them. Coverage is a floor. It tells you a line executed; it tells you nothing about whether the
assertion around it would have noticed if the line were wrong.
A note on what is disclosed here
Every finding is listed with its severity and its disposition, including the ones that remain open.
For findings that are remediated, accepted, or informational, the mechanism is described in full.
For the small number of open findings that are exploitable against a live deployment, this page
states what is wrong, what the impact is, and what the fix is — but not the reproduction recipe.
The complete mechanical detail, the parameters and the executable proofs are held in the internal
audit record and are available to reviewers on request. That is ordinary responsible-disclosure
practice, and it is flagged here rather than done silently, because this register's stated policy is
to publish in full and this is a deliberate exception to it with a stated expiry: remediation.
Post-audit remediation
On 3 August 2026, the four Low assurance-chain findings D13-01 through D13-04 were remediated.
Static analysis is now bound to a runner-owned configuration and complete source identity; storage
layout discovery covers the full reachable type graph and has hostile key-type regressions; the
broadcasting QA path is bound to the connected chain's canonical manifest; and frontend fee-ABI
selection rejects known incompatible pairings and requires an explicit version for unknown test
deployments. These controls are executable in CI rather than relying on the audit's temporary
evidence scripts.
Those remediations do not change the disposition of any open protocol or economic finding and do
not satisfy the independent external-audit gate.
Standing
This was an internal adversarial audit. It is not the independent external security audit that
the production-assurance gates require. That gate remains outstanding, this work does not satisfy
it, and nothing here authorizes a mainnet promotion.
The deployment it examined is a testnet deployment carrying no third-party capital, with a mock
stablecoin, retained operator privileges and concentration limits left fully open — so nothing green
in this round is evidence about a production configuration either.