External review. This review was conducted by a party other than Forest Road. What the engagement did and did not cover is set out under Method and in the report itself, the limits of a review bear on what its findings are worth, and should be read alongside them. It does not by itself authorize a production launch. It reviews the source at the baseline below, which is not necessarily identical to the code deployed on any network. Forest Road Vault is live on Ethereum mainnet; its Solana curator vault remains on devnet and BSC has its own deployment status. An open finding applies only to the product, version and deployment state named by this review. Each review's scope bounds what its clean result is worth. Nothing here is a securities-law representation; token characterization is a matter for counsel.
- Scope
- One source file per review manifest, covering 125 files. Dependency closure was not established, and deployment scripts were outside scope. Cross-file invariants and ceremony controls could therefore not be cleared by silence in this round.
- Method
- Two-reviewer ensemble over every scoped file, producing 317 claims across 88 files, followed by correctness triage, dependency-aware verification, full-suite reruns and remediation packages.
- Reviewed baseline
- 125 production source files across the Ethereum and BSC trees
- Internal report
- audit-reports/corrovera-dual-chain-2026-09-13/CORROVERA-ENSEMBLE-REPORT.md
EN-H1/H2HighSuperseded
Two proposed High claims lacked consensus and failed dependency-aware confirmation
The BSC ClaimBridge mint-gate concern and the ReserveCascade backing-value concern did not survive full interacting-contract review. In particular, the alleged cascade overcount depended on USDfr being counted by backingValue, which the dependency-aware trace disproved.
EN-M-GROUP-1MediumRemediated
Confirmed lifecycle, custody and access-control defects
Supported items included the custody-predicate overreach, one-shot attestation coverage, ACL baseline drift and missing interaction guards. The final remediation verification reran the full historical regression corpus and closed those supported classes.
EN-M-GROUP-2MediumRemediated
PIK payoff, fee withholding and retention coverage gaps
Follow-up review confirmed non-accrual PIK payoff forfeiture, native PIK fee delivery without required withholding and a paired-yield retention check gap. The remediation packages corrected them on the applicable trees and added focused controls.
EN-M-GROUP-3MediumRemediated
Recovery-assessment identity drift under continuous past-due accrual
The one-second expiry behavior was confirmed in the later diff round and fixed with the assessment ratchet described in that review.
EN-SCOPE-1InformationalAccepted
Single-file review could not establish cross-contract or deployment guarantees
Sixty-eight claims stated the missing dependency closure directly. Cross-file invariants, script behavior and live role topology were addressed only by later integration, deployment and fork reviews; they are not retroactively attributed to this round.
How to read the claim count
The review produced 317 claims across 88 of 125 scoped source files. That number is not a count of
317 confirmed defects. Reviewers agreed on some claims, split on others, and two were explicitly
refuted in the original result. Both proposed High claims lacked consensus and were later refuted
after interacting dependencies were visible.
The report's headline table at publication recorded 35 two-reviewer Medium claims and 31 unresolved
Medium claims. Later correctness work consolidated duplicate mechanisms, restored the omitted
historical regression corpus, read the interacting contracts, and corrected the supported issues.
The findings list on this page records the material groups and current status; the full claim
corpus remains in the named report.
Scope limit
Each file was reviewed alone. Dependency closure was explicitly not established, and deployment
scripts were outside scope. Sixty-eight claims named that limitation themselves. The round could
find local defects, but it could not clear cross-contract accounting, role topology, ceremony
validation or deployment behavior.
Later full-suite, dependency-aware, diff and deployed-address reviews supply evidence for the
areas they actually exercised. They do not retroactively expand this review's scope.
High-severity candidates
Neither proposed High survived dependency-aware verification. The apparent ReserveCascade issue
depended on a value being counted by backingValue() that the interacting contract does not count.
The ClaimBridge candidate also failed once its sibling checks and actual call path were included.
The register preserves the proposed rating and marks the group superseded rather than pretending
the original readers agreed.